CVE-2025-38015
MEDIUMLinux Kernel 6.0.9-6.14.7 Use-After-Free in idxd_alloc Error Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc Memory allocated for idxd is not freed if an error occurs during idxd_alloc(). To fix it, free the allocated memory in the reverse order of allocation before exiting the function in case of an error.
References (6)
Core 6
Core References
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
5.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (21)
debian/debian_linux
11.0
linux/Kernel
6.1.0 - 6.1.140linux
linux/Kernel
6.13.0 - 6.14.8linux
linux/Kernel
6.2.0 - 6.6.92linux
linux/Kernel
6.7.0 - 6.12.30linux
Linux/Linux
< 6.1
Linux/Linux
6.0.9 - 6.1
Linux/Linux
6.1
Linux/Linux
6.1.140 - 6.1.*
Linux/Linux
6.12.30 - 6.12.*
... and 11 more
Published
Jun 18, 2025
Tracked Since
Feb 18, 2026