pps: fix warning in pps_register_cdev when register device fail
Summary
| CVE | CVE-2025-40070 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-28 12:15:41 UTC |
| Updated | 2026-07-14 13:17:52 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: pps: fix warning in pps_register_cdev when register device fail Similar to previous commit 2a934fdb01db ("media: v4l2-dev: fix error handling in __video_register_device()"), the release hook should be set before device_register(). Otherwise, when device_register() return error and put_device() try to callback the release function, the below warning may happen. ------------[ cut here ]------------ WARNING: CPU: 1 PID: 4760 at drivers/base/core.c:2567 device_release+0x1bd/0x240 drivers/base/core.c:2567 Modules linked in: CPU: 1 UID: 0 PID: 4760 Comm: syz.4.914 Not tainted 6.17.0-rc3+ #1 NONE RIP: 0010:device_release+0x1bd/0x240 drivers/base/core.c:2567 Call Trace: <TASK> kobject_cleanup+0x136/0x410 lib/kobject.c:689 kobject_release lib/kobject.c:720 [inline] kref_put include/linux/kref.h:65 [inline] kobject_put+0xe9/0x130 lib/kobject.c:737 put_device+0x24/0x30 drivers/base/core.c:3797 pps_register_cdev+0x2da/0x370 drivers/pps/pps.c:402 pps_register_source+0x2f6/0x480 drivers/pps/kapi.c:108 pps_tty_open+0x190/0x310 drivers/pps/clients/pps-ldisc.c:57 tty_ldisc_open+0xa7/0x120 drivers/tty/tty_ldisc.c:432 tty_set_ldisc+0x333/0x780 drivers/tty/tty_ldisc.c:563 tiocsetd drivers/tty/tty_io.c:2429 [inline] tty_ioctl+0x5d1/0x1700 drivers/tty/tty_io.c:2728 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:598 [inline] __se_sys_ioctl fs/ioctl.c:584 [inline] __x64_sys_ioctl+0x194/0x210 fs/ioctl.c:584 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x5f/0x2a0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> Before commit c79a39dc8d06 ("pps: Fix a use-after-free"), pps_register_cdev() call device_create() to create pps->dev, which will init dev->release to device_create_release(). Now the comment is outdated, just remove it. Thanks for the reminder from Calvin Owens, 'kfree_pps' should be removed in pps_register_source() to avoid a double free in the failure case. |
Risk And Classification
EPSS: 0.001930000 probability, percentile 0.091100000 (date 2026-07-14)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 785c78ed0d39d1717cca3ef931d3e51337b5e90e 38c7bb10aae5118dd48fa7a82f7bf93839bcc320 git | Not specified |
| CNA | Linux | Linux | affected 1a7735ab2cb9747518a7416fb5929e85442dec62 2a194707ca27a3b0523023fa8b446e5ec922dc51 git | Not specified |
| CNA | Linux | Linux | affected c4041b6b0a7a3def8cf3f3d6120ff337bc4c40f7 125527db41805693208ee1aacd7f3ffe6a3a489c git | Not specified |
| CNA | Linux | Linux | affected 91932db1d96b2952299ce30c1c693d834d10ace6 4cbd7450a22c5ee4842fc4175ad06c0c82ea53a8 git | Not specified |
| CNA | Linux | Linux | affected cd3bbcb6b3a7caa5ce67de76723b6d8531fb7f64 cf71834a0cfc394c72d62fd6dbb470ee13cf8f5e git | Not specified |
| CNA | Linux | Linux | affected 7e5ee3281dc09014367f5112b6d566ba36ea2d49 f01fa3588e0b3cb1540f56d2c6bd99e5b3810234 git | Not specified |
| CNA | Linux | Linux | affected c79a39dc8d060b9e64e8b0fa9d245d44befeefbe 0f97564a1fb62f34b3b498e2f12caffbe99c004a git | Not specified |
| CNA | Linux | Linux | affected c79a39dc8d060b9e64e8b0fa9d245d44befeefbe b0531cdba5029f897da5156815e3bdafe1e9b88d git | Not specified |
| CNA | Linux | Linux | affected 85241f7de216f8298f6e48540ea13d7dcd100870 git | Not specified |
| CNA | Linux | Linux | affected 5.4.291 5.4.301 semver | Not specified |
| CNA | Linux | Linux | affected 5.10.235 5.10.246 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.179 5.15.195 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.129 6.1.156 semver | Not specified |
| CNA | Linux | Linux | affected 6.6.76 6.6.112 semver | Not specified |
| CNA | Linux | Linux | affected 6.12.13 6.12.53 semver | Not specified |
| CNA | Linux | Linux | affected 6.13.2 6.14 semver | Not specified |
| CNA | Linux | Linux | affected 6.14 | Not specified |
| CNA | Linux | Linux | unaffected 6.14 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.301 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.246 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.195 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.156 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.112 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.53 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.3 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18 * original_commit_for_fix | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/cf71834a0cfc394c72d62fd6dbb470ee13cf8f5e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/125527db41805693208ee1aacd7f3ffe6a3a489c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4cbd7450a22c5ee4842fc4175ad06c0c82ea53a8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2a194707ca27a3b0523023fa8b446e5ec922dc51 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| cert-portal.siemens.com/productcert/html/ssa-019113.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/b0531cdba5029f897da5156815e3bdafe1e9b88d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0f97564a1fb62f34b3b498e2f12caffbe99c004a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f01fa3588e0b3cb1540f56d2c6bd99e5b3810234 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/38c7bb10aae5118dd48fa7a82f7bf93839bcc320 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.