n the Linux kernel, the following vulnerability has been resolved: s390/ism: add release function for struct device According to device_release() in /drivers/base/core.c, a device without a release function is a broken device and must be fixed. The current code directly frees the device after calling device_add() without waiting for other kernel parts to release their references. Thus, a reference could still be held to a struct device, e.g., by sysfs, leading to potential use-after-free issues if a proper release function is not set.
Configuration 1 (hide)
|
13 Mar 2025, 21:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-03-12 10:15
Updated : 2025-10-01 20:18
NVD link : CVE-2025-21856
Mitre link : CVE-2025-21856
CVE.ORG link : CVE-2025-21856
JSON object : View
Use After Free