SB2025070505 - Memory leak in Linux kernel
Published: July 5, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-38190)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the atm_pop_raw() function in net/atm/raw.c, within the vcc_sendmsg() function in net/atm/common.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2252c539c43f9a1431a7e8b34e3c18e9dd77a96d
- https://git.kernel.org/stable/c/287b4f085d2ca3375cf1ee672af27410c64777e8
- https://git.kernel.org/stable/c/3902205eadf35db59dbc2186c2a98b9e6182efa5
- https://git.kernel.org/stable/c/3d828519bd69bfcaabdd942a872679617ef06739
- https://git.kernel.org/stable/c/5e0d00992118e234ebf29d5145c1cc920342777e
- https://git.kernel.org/stable/c/7851263998d4269125fd6cb3fdbfc7c6db853859
- https://git.kernel.org/stable/c/7d6bc28cfe5c8e3a279b4b4bdeed6698b2702685
- https://git.kernel.org/stable/c/c12430edd92fd49a4800b0f3fb395b50cb16bcc1