CVE-2025-37836

MEDIUM EPSS 15.7%
Published May 9, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 9, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: PCI: Fix reference leak in pci_register_host_bridge() If device_register() fails, call put_device() to give up the reference to avoid a memory leak, per the comment at device_register(). Found by code review. [bhelgaas: squash Dan Carpenter's double free fix from https://lore.kernel.org/r/db806a6c-a91b-4e5a-a84b-6b7e01bdac85@stanley.mountain]

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
15.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel*≥4.10  –  <5.10.237
linuxlinux_kernel*≥5.11  –  <5.15.181
linuxlinux_kernel*≥5.16  –  <6.1.136
linuxlinux_kernel*≥6.2  –  <6.6.89
linuxlinux_kernel*≥6.7  –  <6.12.24
linuxlinux_kernel*≥6.13  –  <6.13.12
linuxlinux_kernel*≥6.14  –  <6.14.3
debiandebian_linux11.0any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/3297497ad2246eb9243849bfbbc57a0dea97d76e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/804443c1f27883926de94c849d91f5b7d7d696e9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9707d0c932f41006a2701afc926b232b50e356b4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b783478e0c53ffb4f04f25fb4e21ef7f482b05df
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bbba4c50a2d2a1d3f3bf31cc4b8280cb492bf2c7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bd2a352a0d72575f1842d28c14c10089f0cfe1ae
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f4db1b2c9ae3d013733c302ee70cac943b7070c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f9208aec86226524ec1cb68a09ac70e974ea6536
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
    Mailing ListThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3297497ad2246eb9243849bfbbc57a0dea97d76e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/804443c1f27883926de94c849d91f5b7d7d696e9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9707d0c932f41006a2701afc926b232b50e356b4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b783478e0c53ffb4f04f25fb4e21ef7f482b05df
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bbba4c50a2d2a1d3f3bf31cc4b8280cb492bf2c7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bd2a352a0d72575f1842d28c14c10089f0cfe1ae
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f4db1b2c9ae3d013733c302ee70cac943b7070c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f9208aec86226524ec1cb68a09ac70e974ea6536
    Patch