CVE-2025-37836 Information
Description
In the Linux kernel the following vulnerability has been resolved:
PCI: Fix reference leak in pci_register_host_bridge()
If device_register() fails call put_device() to give up the reference to avoid a memory leak per the comment at device_register().
Found by code review.
[bhelgaas: squash Dan Carpenter’s double free fix from https://lore.kernel.org/r/db806a6c-a91b-4e5a-a84b-6b7e01bdac85@stanley.mountain]
Reference
https://git.kernel.org/stable/c/3297497ad2246eb9243849bfbbc57a0dea97d76e https://git.kernel.org/stable/c/804443c1f27883926de94c849d91f5b7d7d696e9 https://git.kernel.org/stable/c/9707d0c932f41006a2701afc926b232b50e356b4 https://git.kernel.org/stable/c/b783478e0c53ffb4f04f25fb4e21ef7f482b05df https://git.kernel.org/stable/c/bbba4c50a2d2a1d3f3bf31cc4b8280cb492bf2c7 https://git.kernel.org/stable/c/bd2a352a0d72575f1842d28c14c10089f0cfe1ae https://git.kernel.org/stable/c/f4db1b2c9ae3d013733c302ee70cac943b7070c0 https://git.kernel.org/stable/c/f9208aec86226524ec1cb68a09ac70e974ea6536
Share on: