In the Linux kernel, the following vulnerability has been resolved:
net: davicom: fix UAF in dm9000_drv_remove
dm is netdev private data and it cannot be
used after free_netdev() call. Using dm after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of the
function.
This is similar to the issue fixed in commit
ad297cd2db89 ("net: qcom/emac: fix UAF in emac_remove").
This bug is detected by our static analysis tool.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-02-27 02:15
Updated : 2025-11-03 20:17
NVD link : CVE-2025-21715
Mitre link : CVE-2025-21715
CVE.ORG link : CVE-2025-21715
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
