CVE-2025-37746

MEDIUM

Linux Kernel 6.8-6.14.3 - Use-After-Free via Duplicate PCI Device Registration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: perf/dwc_pcie: fix duplicate pci_dev devices During platform_device_register, wrongly using struct device pci_dev as platform_data caused a kmemdup copy of pci_dev. Worse still, accessing the duplicated device leads to list corruption as its mutex content (e.g., list, magic) remains the same as the original.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-704
Status published
Products (8)
linux/Kernel 6.8.0 - 6.14.3linux
Linux/Linux < 6.8
Linux/Linux 6.14.3 - 6.14.*
Linux/Linux 6.15
Linux/Linux 6.8
Linux/Linux af9597adc2f1e3609c67c9792a2469bb64e43ae9 - 7f35b429802a8065aa61e2a3f567089649f4d98e
Linux/Linux af9597adc2f1e3609c67c9792a2469bb64e43ae9 - a71c6fc87b2b9905dc2e38887fe4122287216be9
linux/linux_kernel 6.8 - 6.14.3
Published May 01, 2025
Tracked Since Feb 18, 2026