VYPR
High severity7.8NVD Advisory· Published Aug 16, 2025· Updated Jul 30, 2026

CVE-2025-38542

CVE-2025-38542

Description

In the Linux kernel, the following vulnerability has been resolved:

net: appletalk: Fix device refcount leak in atrtr_create()

When updating an existing route entry in atrtr_create(), the old device reference was not being released before assigning the new device, leading to a device refcount leak. Fix this by calling dev_put() to release the old device reference before holding the new one.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

14
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • Linux/Kernel12 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.13,<5.4.296
    • cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2.6.12
  • osv-coords
    Range: >= 2.6.12, < 5.4.296

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.