CVE-2025-37946
Published: May 20, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs With commit bcb5d6c76903 ("s390/pci: introduce lock to synchronize state of zpci_dev's") the code to ignore power off of a PF that has child VFs was changed from a direct return to a goto to the unlock and pci_dev_put() section. The change however left the existing pci_dev_put() untouched resulting in a doubple put. This can subsequently cause a use after free if the struct pci_dev is released in an unexpected state. Fix this by removing the extra pci_dev_put().
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected bcb5d6c769039c8358a2359e7c3ea5d97ce93108 - < c488f8b53e156d6dcc0514ef0afa3a33376b8f9eaffected bcb5d6c769039c8358a2359e7c3ea5d97ce93108 - < 957529baef142d95e0d1b1bea786675bd47dbe53affected bcb5d6c769039c8358a2359e7c3ea5d97ce93108 - < 05a2538f2b48500cf4e8a0a0ce76623cc5bafcf1 |
Linux | Linux | affected 6.9unaffected 0 - < 6.9unaffected 6.12.29 - <= 6.12.*unaffected 6.14.7 - <= 6.14.*unaffected 6.15 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now