Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-38137


In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: Cancel outstanding rescan work when unregistering It's possible to trigger use-after-free here by: (a) forcing rescan_work_func() to take a long time and (b) utilizing a pwrctrl driver that may be unloaded for some reason Cancel outstanding work to ensure it is finished before we allow our data structures to be cleaned up. [bhelgaas: tidy commit log]


Published

2025-07-03T09:15:28.240

Last Modified

2025-11-20T20:11:34.967

Status

Analyzed

Source

416baaa9-dc9f-4396-8d5f-8c081fb06d67

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 6.15.3 Yes
Operating System linux linux_kernel 6.11 Yes
Operating System linux linux_kernel 6.11 Yes

References