7.8

CVE-2025-37796

wifi: at76c50x: fix use after free access in at76_disconnect

In the Linux kernel, the following vulnerability has been resolved:

wifi: at76c50x: fix use after free access in at76_disconnect

The memory pointed to by priv is freed at the end of at76_delete_device
function (using ieee80211_free_hw). But the code then accesses the udev
field of the freed object to put the USB device. This may also lead to a
memory leak of the usb device. Fix this by using udev from interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.17.1 < 5.4.293
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.237
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.181
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.135
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.88
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.25
Linux ≫ Linux Kernel Version >= 6.13 < 6.14.4
Linux ≫ Linux Kernel Version 3.17 Update -
Linux ≫ Linux Kernel Version 3.17 Update rc5
Linux ≫ Linux Kernel Version 3.17 Update rc6
Linux ≫ Linux Kernel Version 3.17 Update rc7
Linux ≫ Linux Kernel Version 6.15 Update rc1
Linux ≫ Linux Kernel Version 6.15 Update rc2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://git.kernel.org/stable/c/5e7df74745700f059dc117a620e566964a2e8f2c
Patch
https://git.kernel.org/stable/c/7ca513631fa6ad3011b8b9197cdde0f351103704
Patch
https://git.kernel.org/stable/c/a9682bfef2cf3802515a902e964d774e137be1b9
Patch
https://git.kernel.org/stable/c/152721cbae42713ecfbca6847e0f102ee6b19546
Patch
https://git.kernel.org/stable/c/27c7e63b3cb1a20bb78ed4a36c561ea4579fd7da
Patch
https://git.kernel.org/stable/c/3c619aec1f538333b56746d2f796aab1bca5c9a5
Patch
https://git.kernel.org/stable/c/6e4ab3e574c2a335b40fa1f70d1c54fcb58ab33f
Patch
https://git.kernel.org/stable/c/c731cdfddcf1be1590d5ba8c9b508f98e3a2b3d6
Patch
https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html