PT-2025-23154 · Linux+6 · Linux Kernel+6

Published

2025-05-07

·

Updated

2026-05-26

·

CVE-2025-37995

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, related to the kobject put() function. Specifically, in the lookup or create module kobject() function, an internal kobject is created using module ktype. When an error occurs, the call to kobject put() attempts to use an uninitialized completion pointer in module kobject release(). To address this issue, an extra check has been added to ensure that complete() is only required when necessary, making kobject put() safe for module type kobjects.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12334
CVE-2025-37995
DLA-4271-1
DLA-4327-1
ECHO-16F5-9C8C-33F6
OESA-2025-1625
OESA-2025-1626
OESA-2025-1627
OESA-2025-1628
OESA-2025-1629
OESA-2025-2556
SUSE-SU-2025:02249-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02334-1
SUSE-SU-2025:02335-1
SUSE-SU-2025:02538-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20475-1
SUSE-SU-2025:20483-1
SUSE-SU-2025:20493-1
SUSE-SU-2025:20498-1
SUSE-SU-2025_02249-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
SUSE-SU-2025_02334-1
SUSE-SU-2025_02335-1
SUSE-SU-2025_02538-1
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7686-1
USN-7699-1
USN-7699-2
USN-7711-1
USN-7712-1
USN-7712-2
USN-7721-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linux Kernel
Linuxmint
Red Os
Suse
Ubuntu