CVE-2025-37836

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-37836
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37836.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37836
Downstream
Related
Published
2025-05-09T06:41:47.341Z
Modified
2025-11-28T02:35:00.130678Z
Summary
PCI: Fix reference leak in pci_register_host_bridge()
Details

In the Linux kernel, the following vulnerability has been resolved:

PCI: Fix reference leak in pciregisterhost_bridge()

If deviceregister() fails, call putdevice() to give up the reference to avoid a memory leak, per the comment at device_register().

Found by code review.

[bhelgaas: squash Dan Carpenter's double free fix from https://lore.kernel.org/r/db806a6c-a91b-4e5a-a84b-6b7e01bdac85@stanley.mountain]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37836.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4
Fixed
f4db1b2c9ae3d013733c302ee70cac943b7070c0
Fixed
3297497ad2246eb9243849bfbbc57a0dea97d76e
Fixed
b783478e0c53ffb4f04f25fb4e21ef7f482b05df
Fixed
bd2a352a0d72575f1842d28c14c10089f0cfe1ae
Fixed
9707d0c932f41006a2701afc926b232b50e356b4
Fixed
bbba4c50a2d2a1d3f3bf31cc4b8280cb492bf2c7
Fixed
f9208aec86226524ec1cb68a09ac70e974ea6536
Fixed
804443c1f27883926de94c849d91f5b7d7d696e9

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.237
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.181
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.136
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.89
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.24
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.12
Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.14.3