CVE-2025-37909

MEDIUM

Linux Kernel 4.17-6.14.5 - Use-After-Free in LAN743x GSO Descriptor Mapping

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Fix memleak issue when GSO enabled Always map the `skb` to the LS descriptor. Previously skb was mapped to EXT descriptor when the number of fragments is zero with GSO enabled. Mapping the skb to EXT descriptor prevents it from being freed, leading to a memory leak

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 6.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (28)
debian/debian_linux 11.0
linux/Kernel 4.17.0 - 5.4.294linux
linux/Kernel 5.11.0 - 5.15.182linux
linux/Kernel 5.16.0 - 6.1.138linux
linux/Kernel 5.5.0 - 5.10.238linux
linux/Kernel 6.13.0 - 6.14.6linux
linux/Kernel 6.2.0 - 6.6.90linux
linux/Kernel 6.7.0 - 6.12.28linux
Linux/Linux < 4.17
Linux/Linux 23f0703c125be490f70501b6b24ed5645775c56a - 093855ce90177488eac772de4eefbb909033ce5f
... and 18 more
Published May 20, 2025
Tracked Since Feb 18, 2026