Wind River Support Network

HomeDefectsLIN1023-12868
Fixed

LIN1023-12868 : Security Advisory - linux - CVE-2025-37796

Created: May 6, 2025    Updated: May 25, 2025
Resolved Date: May 25, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: at76c50x: fix use after free access in at76_disconnect

The memory pointed to by priv is freed at the end of at76_delete_device
function (using ieee80211_free_hw). But the code then accesses the udev
field of the freed object to put the USB device. This may also lead to a
memory leak of the usb device. Fix this by using udev from interface.

CREATE(Triage):(User=admin) CVE-2025-37796 (https://nvd.nist.gov/vuln/detail/CVE-2025-37796)

CVEs


Live chat
Online