CVE-2025-37980
MEDIUMLinux Kernel 3.13-6.6.87, 6.7.0-6.12.24, 6.13.0-6.14.3 - Use-After-Free in blk_register_queue Error Path
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: block: fix resource leak in blk_register_queue() error path When registering a queue fails after blk_mq_sysfs_register() is successful but the function later encounters an error, we need to clean up the blk_mq_sysfs resources. Add the missing blk_mq_sysfs_unregister() call in the error path to properly clean up these resources and prevent a memory leak.
References (7)
Core 7
Core References
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-019113.html
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
5.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (19)
linux/Kernel
3.13.0 - 6.1.168linux
linux/Kernel
3.13.0 - 6.6.88linux
linux/Kernel
6.13.0 - 6.14.4linux
linux/Kernel
6.2.0 - 6.6.88linux
linux/Kernel
6.7.0 - 6.12.25linux
Linux/Linux
< 3.13
Linux/Linux
3.13
Linux/Linux
320ae51feed5c2f13664aa05a76bec198967e04d - 40f2eb9b531475dd01b683fdaf61ca3cfd03a51e
Linux/Linux
320ae51feed5c2f13664aa05a76bec198967e04d - 41e43134ddda35949974be40520460a12dda3502
Linux/Linux
320ae51feed5c2f13664aa05a76bec198967e04d - 549cbbd14bbec12469ceb279b79c763c8a24224e
... and 9 more
Published
May 20, 2025
Tracked Since
Feb 18, 2026