CVE-2025-38235 Information

Description

In the Linux kernel the following vulnerability has been resolved:

HID: appletb-kbd: fix ppletb_backlight\ backlight device reference counting

During appletb_kbd_probe probe attempts to get the backlight device by name. When this happens backlight_device_get_by_name looks for a device in the backlight class which has name ppletb_backlight\ and upon finding a match it increments the reference count for the device and returns it to the caller. However this reference is never released leading to a reference leak.

Fix this by decrementing the backlight device reference count on removal via put_device and on probe failure.

Reference

https://git.kernel.org/stable/c/4540e41e753a7d69ecd3f5bad51fe620205c3a18 https://git.kernel.org/stable/c/751d5437112a3f387de4ef6d2d1c131068ff7627

CNNVD-202507-592 (Published: 2025-07-06)

Share on: