CVE-2025-37986

In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Invalidate USB device pointers on partner unregistration To avoid using invalid USB device pointers after a Type-C partner disconnects, this patch clears the pointers upon partner unregistration. This ensures a clean state for future connections.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*

History

14 Nov 2025, 16:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: usb: typec: class: Invalidación de punteros de dispositivos USB al cancelar el registro del socio. Para evitar el uso de punteros de dispositivos USB no válidos tras la desconexión de un socio de tipo C, este parche borra los punteros al cancelar el registro del socio. Esto garantiza un estado limpio para futuras conexiones.
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/40966fc9939e85677fdb489dfddfa205baaad03b - () https://git.kernel.org/stable/c/40966fc9939e85677fdb489dfddfa205baaad03b - Patch
References () https://git.kernel.org/stable/c/66e1a887273c6b89f09bc11a40d0a71d5a081a8e - () https://git.kernel.org/stable/c/66e1a887273c6b89f09bc11a40d0a71d5a081a8e - Patch
References () https://git.kernel.org/stable/c/74911338f47c13d1b9470fc50718182bffad42e2 - () https://git.kernel.org/stable/c/74911338f47c13d1b9470fc50718182bffad42e2 - Patch

20 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-20 18:15

Updated : 2025-11-14 16:59


NVD link : CVE-2025-37986

Mitre link : CVE-2025-37986

CVE.ORG link : CVE-2025-37986


JSON object : View

Products Affected

linux

  • linux_kernel