We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-37916

pds_core: remove write-after-free of client_id



Description

In the Linux kernel, the following vulnerability has been resolved: pds_core: remove write-after-free of client_id A use-after-free error popped up in stress testing: [Mon Apr 21 21:21:33 2025] BUG: KFENCE: use-after-free write in pdsc_auxbus_dev_del+0xef/0x160 [pds_core] [Mon Apr 21 21:21:33 2025] Use-after-free write at 0x000000007013ecd1 (in kfence-#47): [Mon Apr 21 21:21:33 2025] pdsc_auxbus_dev_del+0xef/0x160 [pds_core] [Mon Apr 21 21:21:33 2025] pdsc_remove+0xc0/0x1b0 [pds_core] [Mon Apr 21 21:21:33 2025] pci_device_remove+0x24/0x70 [Mon Apr 21 21:21:33 2025] device_release_driver_internal+0x11f/0x180 [Mon Apr 21 21:21:33 2025] driver_detach+0x45/0x80 [Mon Apr 21 21:21:33 2025] bus_remove_driver+0x83/0xe0 [Mon Apr 21 21:21:33 2025] pci_unregister_driver+0x1a/0x80 The actual device uninit usually happens on a separate thread scheduled after this code runs, but there is no guarantee of order of thread execution, so this could be a problem. There's no actual need to clear the client_id at this point, so simply remove the offending code.

Reserved 2025-04-16 | Published 2025-05-20 | Updated 2025-05-26 | Assigner Linux

Product status

Default status
unaffected

10659034c622738bc1bfab8a76fc576c52d5acce before 9b467c5bcdb45a41d2a49fbb9ffca73d1380e99b
affected

10659034c622738bc1bfab8a76fc576c52d5acce before c649b9653ed09196e91d3f4b16b679041b3c42e6
affected

10659034c622738bc1bfab8a76fc576c52d5acce before 26dc701021302f11c8350108321d11763bd81dfe
affected

10659034c622738bc1bfab8a76fc576c52d5acce before dfd76010f8e821b66116dec3c7d90dd2403d1396
affected

Default status
affected

6.4
affected

Any version before 6.4
unaffected

6.6.90
unaffected

6.12.28
unaffected

6.14.6
unaffected

6.15
unaffected

References

git.kernel.org/...c/9b467c5bcdb45a41d2a49fbb9ffca73d1380e99b

git.kernel.org/...c/c649b9653ed09196e91d3f4b16b679041b3c42e6

git.kernel.org/...c/26dc701021302f11c8350108321d11763bd81dfe

git.kernel.org/...c/dfd76010f8e821b66116dec3c7d90dd2403d1396

cve.org (CVE-2025-37916)

nvd.nist.gov (CVE-2025-37916)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-37916

Support options

Helpdesk Chat, Email, Knowledgebase