CVE-2025-38137

high

Description

In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: Cancel outstanding rescan work when unregistering It's possible to trigger use-after-free here by: (a) forcing rescan_work_func() to take a long time and (b) utilizing a pwrctrl driver that may be unloaded for some reason Cancel outstanding work to ensure it is finished before we allow our data structures to be cleaned up. [bhelgaas: tidy commit log]

References

https://git.kernel.org/stable/c/b3ad6d23fec23fbef382ce9ea640c37446593cf5

https://git.kernel.org/stable/c/8b926f237743f020518162c62b93cb7107a2b5eb

Details

Source: Mitre, NVD

Published: 2025-07-03

Updated: 2025-07-03

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Severity: High

EPSS

EPSS: 0.00018