CVE-2025-38390

MEDIUM

Linux Kernel 6.7-6.12.37, 6.13-6.15.6 - Use-After-Free in ARM FFA Notifier Callback

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix memory leak by freeing notifier callback node Commit e0573444edbf ("firmware: arm_ffa: Add interfaces to request notification callbacks") adds support for notifier callbacks by allocating and inserting a callback node into a hashtable during registration of notifiers. However, during unregistration, the code only removes the node from the hashtable without freeing the associated memory, resulting in a memory leak. Resolve the memory leak issue by ensuring the allocated notifier callback node is properly freed after it is removed from the hashtable entry.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (12)
linux/Kernel 6.13.0 - 6.15.6linux
linux/Kernel 6.7.0 - 6.12.37linux
Linux/Linux < 6.7
Linux/Linux 6.12.37 - 6.12.*
Linux/Linux 6.15.6 - 6.15.*
Linux/Linux 6.16
Linux/Linux 6.7
Linux/Linux e0573444edbf4ee7e3c191d3d08a4ccbd26628be - 076fa20b4f5737c34921dbb152f9efceaee571b2
Linux/Linux e0573444edbf4ee7e3c191d3d08a4ccbd26628be - 938827c440564b2cf2f9b804d1fe81ce8267eded
Linux/Linux e0573444edbf4ee7e3c191d3d08a4ccbd26628be - a833d31ad867103ba72a0b73f3606f4ab8601719
... and 2 more
Published Jul 25, 2025
Tracked Since Feb 18, 2026