CVE-2025-37909

MEDIUM

Linux kernel - Memory Corruption

Title source: llm

Description

In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Fix memleak issue when GSO enabled Always map the `skb` to the LS descriptor. Previously skb was mapped to EXT descriptor when the number of fragments is zero with GSO enabled. Mapping the skb to EXT descriptor prevents it from being freed, leading to a memory leak

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 13.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-401
Status published

Affected Products (13)

linux/linux_kernel < 5.4.294
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
debian/debian_linux
linux/Kernel < 5.4.294linux
linux/Kernel < 5.10.238linux
linux/Kernel < 5.15.182linux
linux/Kernel < 6.1.138linux
linux/Kernel < 6.6.90linux
linux/Kernel < 6.12.28linux
linux/Kernel < 6.14.6linux

Timeline

Published May 20, 2025
Tracked Since Feb 18, 2026