cbcvebase.
CVE-2025-37852
published 2025-05-09

CVE-2025-37852: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() Add error…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() Add error handling to propagate amdgpu_cgs_create_device() failures to the caller. When amdgpu_cgs_create_device() fails, release hwmgr and return -ENOMEM to prevent null pointer dereference. [v1]->[v2]: Change error code from -EINVAL to -ENOMEM. Free hwmgr.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= b905090d2bae2e6189511714a7b88691b439c5a1 < 55ef52c30c3e747f145a64de96192e37a8fed67055ef52c30c3e747f145a64de96192e37a8fed670
linuxlinux>= b905090d2bae2e6189511714a7b88691b439c5a1 < f8693e1bae9c08233a2f535c3f412e157df32b33f8693e1bae9c08233a2f535c3f412e157df32b33
linuxlinux>= b905090d2bae2e6189511714a7b88691b439c5a1 < dc4380f34613eaae997b3ed263bd1cb3d0fd0075dc4380f34613eaae997b3ed263bd1cb3d0fd0075
linuxlinux>= b905090d2bae2e6189511714a7b88691b439c5a1 < 22ea19cc089013b55c240134dbb2797700ff5a6a22ea19cc089013b55c240134dbb2797700ff5a6a
linuxlinux>= b905090d2bae2e6189511714a7b88691b439c5a1 < b784734811438f11533e2fb9e0deb327844bdb56b784734811438f11533e2fb9e0deb327844bdb56
linuxlinux>= b905090d2bae2e6189511714a7b88691b439c5a1 < 1435e895d4fc967d64e9f5bf81e992ac32f5ac761435e895d4fc967d64e9f5bf81e992ac32f5ac76
linuxlinux_kernel< 6.1.1356.1.135
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.36.14.3
linuxlinux_kernel>= 6.2 < 6.6.886.6.88
linuxlinux_kernel>= 6.7 < 6.12.246.12.24
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.