CVE-2025-37800: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference in dev_uevent() If userspace reads "uevent" device attribute at the same time as another threads unbinds the device from its driver, change to dev->driver from a valid pointer to NULL may result in crash. Fix this by using READ_ONCE() when fetching the pointer, and take bus' drivers klist lock to make sure driver instance will not disappear while we access it. Use WRITE_ONCE() when setting the driver pointer to ensure there is no tearing.

Affected products

  • Linux Linux Kernel: before 6.6.89 (fixed in 6.6.89); from 6.7, before 6.12.26 (fixed in 6.12.26); from 6.13, before 6.14.5 (fixed in 6.14.5); version 6.15 only

Published 2025-05-08. Last modified 2026-07-30.