CVE-2025-37852: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() Add error handling to propagate amdgpu_cgs_create_device() failures to the caller. When amdgpu_cgs_create_device() fails, release hwmgr and return -ENOMEM to prevent null pointer dereference. [v1]->[v2]: Change error code from -EINVAL to -ENOMEM. Free hwmgr.
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: before 6.1.135 (fixed in 6.1.135); from 6.2, before 6.6.88 (fixed in 6.6.88); from 6.7, before 6.12.24 (fixed in 6.12.24); from 6.13, before 6.13.12 (fixed in 6.13.12); from 6.14, before 6.14.3 (fixed in 6.14.3)
Published 2025-05-09. Last modified 2026-06-17.