๐Ÿ” CVE Alert

CVE-2025-37946

UNKNOWN 0.0

s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs With commit bcb5d6c76903 ("s390/pci: introduce lock to synchronize state of zpci_dev's") the code to ignore power off of a PF that has child VFs was changed from a direct return to a goto to the unlock and pci_dev_put() section. The change however left the existing pci_dev_put() untouched resulting in a doubple put. This can subsequently cause a use after free if the struct pci_dev is released in an unexpected state. Fix this by removing the extra pci_dev_put().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 20, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bcb5d6c769039c8358a2359e7c3ea5d97ce93108 < c488f8b53e156d6dcc0514ef0afa3a33376b8f9e bcb5d6c769039c8358a2359e7c3ea5d97ce93108 < 957529baef142d95e0d1b1bea786675bd47dbe53 bcb5d6c769039c8358a2359e7c3ea5d97ce93108 < 05a2538f2b48500cf4e8a0a0ce76623cc5bafcf1
Linux / Linux
6.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c488f8b53e156d6dcc0514ef0afa3a33376b8f9e git.kernel.org: https://git.kernel.org/stable/c/957529baef142d95e0d1b1bea786675bd47dbe53 git.kernel.org: https://git.kernel.org/stable/c/05a2538f2b48500cf4e8a0a0ce76623cc5bafcf1