CVE-2025-37909

MEDIUM EPSS 6.4%
Published May 20, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 20, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Fix memleak issue when GSO enabled Always map the `skb` to the LS descriptor. Previously skb was mapped to EXT descriptor when the number of fragments is zero with GSO enabled. Mapping the skb to EXT descriptor prevents it from being freed, leading to a memory leak

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
6.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-401

Affected Products 12

VendorProductVersionRange
linuxlinux_kernel*≥4.17  –  <5.4.294
linuxlinux_kernel*≥5.5  –  <5.10.238
linuxlinux_kernel*≥5.11  –  <5.15.182
linuxlinux_kernel*≥5.16  –  <6.1.138
linuxlinux_kernel*≥6.2  –  <6.6.90
linuxlinux_kernel*≥6.7  –  <6.12.28
linuxlinux_kernel*≥6.13  –  <6.14.6
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
debiandebian_linux11.0any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/093855ce90177488eac772de4eefbb909033ce5f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/189b05f189cac9fd233ef04d31cb5078c4d09c39
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2d52e2e38b85c8b7bc00dca55c2499f46f8c8198
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6c65ee5ad632eb8dcd3a91cf5dc99b22535f44d9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a0e0efbabbbe6a1859bc31bf65237ce91e124b9b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/dae1ce27ceaea7e1522025b15252e3cc52802622
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/df993daa4c968b4b23078eacc248f6502ede8664
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f42c18e2f14c1b1fdd2a5250069a84bc854c398c
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html
    Mailing List
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Mailing List

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/093855ce90177488eac772de4eefbb909033ce5f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/189b05f189cac9fd233ef04d31cb5078c4d09c39
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2d52e2e38b85c8b7bc00dca55c2499f46f8c8198
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6c65ee5ad632eb8dcd3a91cf5dc99b22535f44d9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a0e0efbabbbe6a1859bc31bf65237ce91e124b9b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/dae1ce27ceaea7e1522025b15252e3cc52802622
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/df993daa4c968b4b23078eacc248f6502ede8664
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f42c18e2f14c1b1fdd2a5250069a84bc854c398c
    Patch