SB2025050964 - Memory leak in Linux kernel wangxun ngbe driver
Published: May 9, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-37874)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the ngbe_probe() and wx_clear_interrupt_scheme() functions in drivers/net/ethernet/wangxun/ngbe/ngbe_main.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/397487338eff1891c4654ce7deaafbf72a1688b2
- https://git.kernel.org/stable/c/7c2b66a31c7a4866400f7e6fb43cb32021bfca01
- https://git.kernel.org/stable/c/8335a3feb9d0d97e5e8f76d38b6bb8573d5b4a29
- https://git.kernel.org/stable/c/88fa80021b77732bc98f73fb69d69c7cc37b9f0d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.25
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.88