{"id":"DEBIAN-CVE-2025-37916","details":"In the Linux kernel, the following vulnerability has been resolved:  pds_core: remove write-after-free of client_id  A use-after-free error popped up in stress testing:  [Mon Apr 21 21:21:33 2025] BUG: KFENCE: use-after-free write in pdsc_auxbus_dev_del+0xef/0x160 [pds_core] [Mon Apr 21 21:21:33 2025] Use-after-free write at 0x000000007013ecd1 (in kfence-#47): [Mon Apr 21 21:21:33 2025]  pdsc_auxbus_dev_del+0xef/0x160 [pds_core] [Mon Apr 21 21:21:33 2025]  pdsc_remove+0xc0/0x1b0 [pds_core] [Mon Apr 21 21:21:33 2025]  pci_device_remove+0x24/0x70 [Mon Apr 21 21:21:33 2025]  device_release_driver_internal+0x11f/0x180 [Mon Apr 21 21:21:33 2025]  driver_detach+0x45/0x80 [Mon Apr 21 21:21:33 2025]  bus_remove_driver+0x83/0xe0 [Mon Apr 21 21:21:33 2025]  pci_unregister_driver+0x1a/0x80  The actual device uninit usually happens on a separate thread scheduled after this code runs, but there is no guarantee of order of thread execution, so this could be a problem.  There's no actual need to clear the client_id at this point, so simply remove the offending code.","modified":"2026-08-27T23:05:28.875572268Z","published":"2025-05-20T16:15:28.170Z","upstream":["CVE-2025-37916"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-37916"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37916.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37916.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}