CVE-2025-38235 Information
Description
In the Linux kernel the following vulnerability has been resolved:
HID: appletb-kbd: fix ppletb_backlight\ backlight device reference counting
During appletb_kbd_probe probe attempts to get the backlight device by name. When this happens backlight_device_get_by_name looks for a device in the backlight class which has name ppletb_backlight\ and upon finding a match it increments the reference count for the device and returns it to the caller. However this reference is never released leading to a reference leak.
Fix this by decrementing the backlight device reference count on removal via put_device and on probe failure.
Reference
https://git.kernel.org/stable/c/4540e41e753a7d69ecd3f5bad51fe620205c3a18 https://git.kernel.org/stable/c/751d5437112a3f387de4ef6d2d1c131068ff7627
Related CNNVD
CNNVD-202507-592 (Published: 2025-07-06)
Share on: