7.8

CVE-2025-38421

platform/x86/amd: pmf: Use device managed allocations

In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd: pmf: Use device managed allocations

If setting up smart PC fails for any reason then this can lead to
a double free when unloading amd-pmf.  This is because dev->buf was
freed but never set to NULL and is again freed in amd_pmf_remove().

To avoid subtle allocation bugs in failures leading to a double free
change all allocations into device managed allocations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.12.23 < 6.13
Linux ≫ Linux Kernel Version >= 6.13.11 < 6.14
Linux ≫ Linux Kernel Version >= 6.14.1 < 6.15.4
Linux ≫ Linux Kernel Version 6.14 Update -
Linux ≫ Linux Kernel Version 6.14 Update rc7
Linux ≫ Linux Kernel Version 6.16 Update rc1
Linux ≫ Linux Kernel Version 6.16 Update rc2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://git.kernel.org/stable/c/0d10b532f861253c283863522d59d099fcb0796d
Patch
https://git.kernel.org/stable/c/d9db3a941270d92bbd1a6a6b54a10324484f2f2d
Patch