cbcvebase.
CVE-2025-21856
published 2025-03-12

CVE-2025-21856: In the Linux kernel, the following vulnerability has been resolved: s390/ism: add release function for struct device According to device_release() in…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.4th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/ism: add release function for struct device According to device_release() in /drivers/base/core.c, a device without a release function is a broken device and must be fixed. The current code directly frees the device after calling device_add() without waiting for other kernel parts to release their references. Thus, a reference could still be held to a struct device, e.g., by sysfs, leading to potential use-after-free issues if a proper release function is not set.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.17-1 (forky)linux 6.12.17-1 (forky)
linuxlinux
linuxlinux>= 8c81ba20349daf9f7e58bb05a0c12f4b71813a30 < 940d15254d2216b585558bcf36312da50074e711940d15254d2216b585558bcf36312da50074e711
linuxlinux>= 8c81ba20349daf9f7e58bb05a0c12f4b71813a30 < 0505ff2936f166405d81d0d454a81d9c141243440505ff2936f166405d81d0d454a81d9c14124344
linuxlinux>= 8c81ba20349daf9f7e58bb05a0c12f4b71813a30 < e26e8ac27351f457091459a0a355bacd06d5bb2be26e8ac27351f457091459a0a355bacd06d5bb2b
linuxlinux>= 8c81ba20349daf9f7e58bb05a0c12f4b71813a30 < 915e34d5ad35a6a9e56113f852ade4a730fb88f0915e34d5ad35a6a9e56113f852ade4a730fb88f0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 6.13 < 6.13.56.13.5
linuxlinux_kernel>= 6.3 < 6.6.806.6.80
linuxlinux_kernel>= 6.7 < 6.12.176.12.17
msrcazl3_kernel_6.6.78.1-3_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.