cbcvebase.
CVE-2025-37836
published 2025-05-09

CVE-2025-37836: In the Linux kernel, the following vulnerability has been resolved: PCI: Fix reference leak in pci_register_host_bridge() If device_register() fails, call…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.4th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI: Fix reference leak in pci_register_host_bridge() If device_register() fails, call put_device() to give up the reference to avoid a memory leak, per the comment at device_register(). Found by code review. [bhelgaas: squash Dan Carpenter's double free fix from https://lore.kernel.org/r/[email protected]]

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < f4db1b2c9ae3d013733c302ee70cac943b7070c0f4db1b2c9ae3d013733c302ee70cac943b7070c0
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < 3297497ad2246eb9243849bfbbc57a0dea97d76e3297497ad2246eb9243849bfbbc57a0dea97d76e
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < b783478e0c53ffb4f04f25fb4e21ef7f482b05dfb783478e0c53ffb4f04f25fb4e21ef7f482b05df
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < bd2a352a0d72575f1842d28c14c10089f0cfe1aebd2a352a0d72575f1842d28c14c10089f0cfe1ae
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < 9707d0c932f41006a2701afc926b232b50e356b49707d0c932f41006a2701afc926b232b50e356b4
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < bbba4c50a2d2a1d3f3bf31cc4b8280cb492bf2c7bbba4c50a2d2a1d3f3bf31cc4b8280cb492bf2c7
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < f9208aec86226524ec1cb68a09ac70e974ea6536f9208aec86226524ec1cb68a09ac70e974ea6536
linuxlinux>= 37d6a0a6f4700ad3ae7bbf8db38b4557e97b3fe4 < 804443c1f27883926de94c849d91f5b7d7d696e9804443c1f27883926de94c849d91f5b7d7d696e9
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.10 < 5.10.2375.10.237
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.36.14.3
linuxlinux_kernel>= 6.2 < 6.6.896.6.89

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.