CVE-2025-37817
HIGHLinux kernel - Use After Free
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: mcb: fix a double free bug in chameleon_parse_gdd() In chameleon_parse_gdd(), if mcb_device_register() fails, 'mdev' would be released in mcb_device_register() via put_device(). Thus, goto 'err' label and free 'mdev' again causes a double free. Just return if mcb_device_register() fails.
References (10)
Scores
CVSS v3
7.8
EPSS
0.0007
EPSS Percentile
20.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-415
Status
published
Affected Products (12)
linux/linux_kernel
< 5.4.293
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
debian/debian_linux
linux/Kernel
< 5.4.293linux
linux/Kernel
< 5.10.237linux
linux/Kernel
< 5.15.181linux
linux/Kernel
< 6.1.136linux
linux/Kernel
< 6.6.89linux
linux/Kernel
< 6.12.26linux
linux/Kernel
< 6.14.5linux
Timeline
Published
May 08, 2025
Tracked Since
Feb 18, 2026