CVE Database
/

CVE-2025-37946

Back to search

CVE-2025-37946

Published: May 20, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs With commit bcb5d6c76903 ("s390/pci: introduce lock to synchronize state of zpci_dev's") the code to ignore power off of a PF that has child VFs was changed from a direct return to a goto to the unlock and pci_dev_put() section. The change however left the existing pci_dev_put() untouched resulting in a doubple put. This can subsequently cause a use after free if the struct pci_dev is released in an unexpected state. Fix this by removing the extra pci_dev_put().

VendorProductVersions

Linux

Linux

affected
bcb5d6c769039c8358a2359e7c3ea5d97ce93108 - < c488f8b53e156d6dcc0514ef0afa3a33376b8f9e
affected
bcb5d6c769039c8358a2359e7c3ea5d97ce93108 - < 957529baef142d95e0d1b1bea786675bd47dbe53
affected
bcb5d6c769039c8358a2359e7c3ea5d97ce93108 - < 05a2538f2b48500cf4e8a0a0ce76623cc5bafcf1

Linux

Linux

affected
6.9
unaffected
0 - < 6.9
unaffected
6.12.29 - <= 6.12.*
unaffected
6.14.7 - <= 6.14.*
unaffected
6.15 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now