cbcvebase.
CVE-2025-23144
published 2025-05-01

CVE-2025-23144: In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.1th percentile
In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects the following issue on led-backlight removal: [ 142.315935] ------------[ cut here ]------------ [ 142.315954] WARNING: CPU: 2 PID: 292 at drivers/leds/led-core.c:455 led_sysfs_enable+0x54/0x80 ... [ 142.500725] Call trace: [ 142.503176] led_sysfs_enable+0x54/0x80 (P) [ 142.507370] led_bl_remove+0x80/0xa8 [led_bl] [ 142.511742] platform_remove+0x30/0x58 [ 142.515501] device_remove+0x54/0x90 ... Indeed, led_sysfs_enable() has to be called with the led_access lock held. Hold the lock when calling led_sysfs_disable().

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 87d947a0607be384bfe7bb0935884a711e35ca0787d947a0607be384bfe7bb0935884a711e35ca07
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 74c7d67a3c305fc1fa03c32a838e8446fb7aee1474c7d67a3c305fc1fa03c32a838e8446fb7aee14
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < b447885ec9130cf86f355e011dc6b94d6ccfb5b7b447885ec9130cf86f355e011dc6b94d6ccfb5b7
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 1c82f5a393d8b9a5c1ea032413719862098afd4b1c82f5a393d8b9a5c1ea032413719862098afd4b
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 61a5c565fd2442d3128f3bab5f022658adc3a4e661a5c565fd2442d3128f3bab5f022658adc3a4e6
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 11d128f7eacec276c75cf4712880a6307ca9c88511d128f7eacec276c75cf4712880a6307ca9c885
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < b8ddf5107f53789448900f04fa220f34cd2f777eb8ddf5107f53789448900f04fa220f34cd2f777e
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 276822a00db3c1061382b41e72cafc09d6a0ec30276822a00db3c1061382b41e72cafc09d6a0ec30
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 5.6.1 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.36.14.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.