{"id":"CVE-2025-40070","title":"pps: fix warning in pps_register_cdev when register device fail","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\npps: fix warning in pps_register_cdev when register device fail\n\nSimilar to previous commit 2a934fdb01db (\"media: v4l2-dev: fix error\nhandling in __video_register_devic…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 785c78ed0d39d1717cca3ef931d3e51337b5e90e < 38c7bb10aae5118dd48fa7a82f7bf93839bcc320","Linux >= 1a7735ab2cb9747518a7416fb5929e85442dec62 < 2a194707ca27a3b0523023fa8b446e5ec922dc51","Linux >= c4041b6b0a7a3def8cf3f3d6120ff337bc4c40f7 < 125527db41805693208ee1aacd7f3ffe6a3a489c","Linux >= 91932db1d96b2952299ce30c1c693d834d10ace6 < 4cbd7450a22c5ee4842fc4175ad06c0c82ea53a8","Linux >= cd3bbcb6b3a7caa5ce67de76723b6d8531fb7f64 < cf71834a0cfc394c72d62fd6dbb470ee13cf8f5e","Linux >= 7e5ee3281dc09014367f5112b6d566ba36ea2d49 < f01fa3588e0b3cb1540f56d2c6bd99e5b3810234","Linux >= c79a39dc8d060b9e64e8b0fa9d245d44befeefbe < 0f97564a1fb62f34b3b498e2f12caffbe99c004a","Linux >= c79a39dc8d060b9e64e8b0fa9d245d44befeefbe < b0531cdba5029f897da5156815e3bdafe1e9b88d","Linux 85241f7de216f8298f6e48540ea13d7dcd100870","Linux >= 5.4.291 < 5.4.301","Linux >= 5.10.235 < 5.10.246","Linux >= 5.15.179 < 5.15.195","Linux >= 6.1.129 < 6.1.156","Linux >= 6.6.76 < 6.6.112","Linux >= 6.12.13 < 6.12.53","Linux >= 6.13.2 < 6.14","Linux 6.14"],"published":"2025-10-28","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:42:45.157Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-40070","references":[{"url":"https://git.kernel.org/stable/c/38c7bb10aae5118dd48fa7a82f7bf93839bcc320"},{"url":"https://git.kernel.org/stable/c/2a194707ca27a3b0523023fa8b446e5ec922dc51"},{"url":"https://git.kernel.org/stable/c/125527db41805693208ee1aacd7f3ffe6a3a489c"},{"url":"https://git.kernel.org/stable/c/4cbd7450a22c5ee4842fc4175ad06c0c82ea53a8"},{"url":"https://git.kernel.org/stable/c/cf71834a0cfc394c72d62fd6dbb470ee13cf8f5e"},{"url":"https://git.kernel.org/stable/c/f01fa3588e0b3cb1540f56d2c6bd99e5b3810234"},{"url":"https://git.kernel.org/stable/c/0f97564a1fb62f34b3b498e2f12caffbe99c004a"},{"url":"https://git.kernel.org/stable/c/b0531cdba5029f897da5156815e3bdafe1e9b88d"}],"tags":["cve.org"],"epss":0.00218,"epssPercentile":0.12474,"ingestedAt":"2026-09-08T15:33:26.996Z","slug":"CVE-2025-40070","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\npps: fix warning in pps_register_cdev when register device fail\n\nSimilar to previous commit 2a934fdb01db (\"media: v4l2-dev: fix error\nhandling in __video_register_device()\"), the release hook should be set\nbefore device_register(). Otherwise, when device_register() return error\nand put_device() try to callback the release function, the below warning\nmay happen.\n\n  ------------[ cut here ]------------\n  WARNING: CPU: 1 PID: 4760 at drivers/base/core.c:2567 device_release+0x1bd/0x240 drivers/base/core.c:2567\n  Modules linked in:\n  CPU: 1 UID: 0 PID: 4760 Comm: syz.4.914 Not tainted 6.17.0-rc3+ #1 NONE\n  RIP: 0010:device_release+0x1bd/0x240 drivers/base/core.c:2567\n  Call Trace:\n   <TASK>\n   kobject_cleanup+0x136/0x410 lib/kobject.c:689\n   kobject_release lib/kobject.c:720 [inline]\n   kref_put include/linux/kref.h:65 [inline]\n   kobject_put+0xe9/0x130 lib/kobject.c:737\n   put_device+0x24/0x30 drivers/base/core.c:3797\n   pps_register_cdev+0x2da/0x370 drivers/pps/pps.c:402\n   pps_register_source+0x2f6/0x480 drivers/pps/kapi.c:108\n   pps_tty_open+0x190/0x310 drivers/pps/clients/pps-ldisc.c:57\n   tty_ldisc_open+0xa7/0x120 drivers/tty/tty_ldisc.c:432\n   tty_set_ldisc+0x333/0x780 drivers/tty/tty_ldisc.c:563\n   tiocsetd drivers/tty/tty_io.c:2429 [inline]\n   tty_ioctl+0x5d1/0x1700 drivers/tty/tty_io.c:2728\n   vfs_ioctl fs/ioctl.c:51 [inline]\n   __do_sys_ioctl fs/ioctl.c:598 [inline]\n   __se_sys_ioctl fs/ioctl.c:584 [inline]\n   __x64_sys_ioctl+0x194/0x210 fs/ioctl.c:584\n   do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n   do_syscall_64+0x5f/0x2a0 arch/x86/entry/syscall_64.c:94\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n   </TASK>\n\nBefore commit c79a39dc8d06 (\"pps: Fix a use-after-free\"),\npps_register_cdev() call device_create() to create pps->dev, which will\ninit dev->release to device_create_release(). Now the comment is outdated,\njust remove it.\n\nThanks for the reminder from Calvin Owens, 'kfree_pps' should be removed\nin pps_register_source() to avoid a double free in the failure case.\n\n## Affected\n\n- `Linux >= 785c78ed0d39d1717cca3ef931d3e51337b5e90e < 38c7bb10aae5118dd48fa7a82f7bf93839bcc320`\n- `Linux >= 1a7735ab2cb9747518a7416fb5929e85442dec62 < 2a194707ca27a3b0523023fa8b446e5ec922dc51`\n- `Linux >= c4041b6b0a7a3def8cf3f3d6120ff337bc4c40f7 < 125527db41805693208ee1aacd7f3ffe6a3a489c`\n- `Linux >= 91932db1d96b2952299ce30c1c693d834d10ace6 < 4cbd7450a22c5ee4842fc4175ad06c0c82ea53a8`\n- `Linux >= cd3bbcb6b3a7caa5ce67de76723b6d8531fb7f64 < cf71834a0cfc394c72d62fd6dbb470ee13cf8f5e`\n- `Linux >= 7e5ee3281dc09014367f5112b6d566ba36ea2d49 < f01fa3588e0b3cb1540f56d2c6bd99e5b3810234`\n- `Linux >= c79a39dc8d060b9e64e8b0fa9d245d44befeefbe < 0f97564a1fb62f34b3b498e2f12caffbe99c004a`\n- `Linux >= c79a39dc8d060b9e64e8b0fa9d245d44befeefbe < b0531cdba5029f897da5156815e3bdafe1e9b88d`\n- `Linux 85241f7de216f8298f6e48540ea13d7dcd100870`\n- `Linux >= 5.4.291 < 5.4.301`\n- `Linux >= 5.10.235 < 5.10.246`\n- `Linux >= 5.15.179 < 5.15.195`\n- `Linux >= 6.1.129 < 6.1.156`\n- `Linux >= 6.6.76 < 6.6.112`\n- `Linux >= 6.12.13 < 6.12.53`\n- `Linux >= 6.13.2 < 6.14`\n- `Linux 6.14`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}