CVE-2025-37817

Source
https://cve.org/CVERecord?id=CVE-2025-37817
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37817.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37817
Downstream
Published
2025-05-08T06:26:12.683Z
Modified
2026-05-07T04:18:33.458872Z
Summary
mcb: fix a double free bug in chameleon_parse_gdd()
Details

In the Linux kernel, the following vulnerability has been resolved:

mcb: fix a double free bug in chameleonparsegdd()

In chameleonparsegdd(), if mcbdeviceregister() fails, 'mdev' would be released in mcbdeviceregister() via putdevice(). Thus, goto 'err' label and free 'mdev' again causes a double free. Just return if mcbdevice_register() fails.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37817.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3764e82e5150d87b205c10cd78a9c9ab86fbfa51
Fixed
d70184958b0ea8c0fd52e2b456654b503e769fc8
Fixed
4ffe8c9fb561e4427dd1a3056cd5b3685b74f78d
Fixed
59f993cd36b6e28a394ba3d977e8ffe5c9884e3b
Fixed
c5b8a549ef1fcc6066b037a3962c79d60465ba0b
Fixed
96838eb1836fd372e42be5db84f0b333b65146a6
Fixed
df1a5d5c6134224f9298e5189230f9d29ae50cac
Fixed
bcc7d58ee5173e34306026bd01e1fbf75e169d37
Fixed
7c7f1bfdb2249f854a736d9b79778c7e5a29a150

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37817.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.15.0
Fixed
5.4.293
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.237
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.181
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.136
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.89
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.26
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37817.json"