CVE-2025-37909
MEDIUMLinux Kernel 4.17-6.14.5 - Use-After-Free in LAN743x GSO Descriptor Mapping
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Fix memleak issue when GSO enabled Always map the `skb` to the LS descriptor. Previously skb was mapped to EXT descriptor when the number of fragments is zero with GSO enabled. Mapping the skb to EXT descriptor prevents it from being freed, leading to a memory leak
References (10)
Core 10
Core References
Scores
CVSS v3
5.5
EPSS
0.0017
EPSS Percentile
6.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (28)
debian/debian_linux
11.0
linux/Kernel
4.17.0 - 5.4.294linux
linux/Kernel
5.11.0 - 5.15.182linux
linux/Kernel
5.16.0 - 6.1.138linux
linux/Kernel
5.5.0 - 5.10.238linux
linux/Kernel
6.13.0 - 6.14.6linux
linux/Kernel
6.2.0 - 6.6.90linux
linux/Kernel
6.7.0 - 6.12.28linux
Linux/Linux
< 4.17
Linux/Linux
23f0703c125be490f70501b6b24ed5645775c56a - 093855ce90177488eac772de4eefbb909033ce5f
... and 18 more
Published
May 20, 2025
Tracked Since
Feb 18, 2026