Security Advisory

CVE-2025-37796

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-05-01 13:07:27
Last updated 2026-05-11 21:15:19
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: at76c50x: fix use after free access in at76_disconnect The memory pointed to by priv is freed at the end of at76_delete_device function (using ieee80211_free_hw). But the code then accesses the udev field of the freed object to put the USB device. This may also lead to a memory leak of the usb device. Fix this by using udev from interface.