PT-2025-20494 · Linux+4 · Linux Kernel+4

Published

2025-03-11

·

Updated

2026-02-02

·

CVE-2025-37843

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A long-standing race condition in the Linux kernel's PCI hotplug functionality can lead to a deadlock when hot-removing nested PCI hotplug ports. This issue occurs when a parent hotplug port acquires a lock and waits for a child port to unbind, while the child port attempts to acquire the same lock to remove its own children. The deadlock only happens if the parent acquires the lock first. A recent commit increased the frequency of this deadlock when removing multiple Thunderbolt devices during system sleep. The issue arises from the inability to reliably differentiate between device replacement and removal.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12342
CVE-2025-37843
USN-7594-1
USN-7594-2
USN-7594-3
USN-7606-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu