CVE-2025-39951

HIGH

Linux Kernel 5.5-6.16.9 Use-After-Free in virtio_uml Probe

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: um: virtio_uml: Fix use-after-free after put_device in probe When register_virtio_device() fails in virtio_uml_probe(), the code sets vu_dev->registered = 1 even though the device was not successfully registered. This can lead to use-after-free or other issues.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (24)
linux/Kernel 5.11.0 - 5.15.194linux
linux/Kernel 5.16.0 - 6.1.154linux
linux/Kernel 5.5.0 - 5.10.245linux
linux/Kernel 6.13.0 - 6.16.9linux
linux/Kernel 6.2.0 - 6.6.108linux
linux/Kernel 6.7.0 - 6.12.49linux
Linux/Linux < 5.5
Linux/Linux 04e5b1fb01834a602acaae2276b67a783a8c6159 - 00e98b5a69034b251bb36dc6e7123d7648e218e4
Linux/Linux 04e5b1fb01834a602acaae2276b67a783a8c6159 - 14c231959a16ca41bfdcaede72483362a8c645d7
Linux/Linux 04e5b1fb01834a602acaae2276b67a783a8c6159 - 4f364023ddcfe83f7073b973a9cb98584b7f2a46
... and 14 more
Published Oct 04, 2025
Tracked Since Feb 18, 2026