SB2025092207 - Memory leak in Linux kernel net ppp driver
Published: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-39847)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the pad_compress_skb() and ppp_send_frame() functions in drivers/net/ppp/ppp_generic.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0b21e9cd4559102da798bdcba453b64ecd7be7ee
- https://git.kernel.org/stable/c/1d8b354eafb8876d8bdb1bef69c7d2438aacfbe8
- https://git.kernel.org/stable/c/33a5bac5f14772730d2caf632ae97b6c2ee95044
- https://git.kernel.org/stable/c/4844123fe0b853a4982c02666cb3fd863d701d50
- https://git.kernel.org/stable/c/631fc8ab5beb9e0ec8651fb9875b9a968e7b4ae4
- https://git.kernel.org/stable/c/85c1c86a67e09143aa464e9bf09c397816772348
- https://git.kernel.org/stable/c/87a35a36742df328d0badf4fbc2e56061c15846c
- https://git.kernel.org/stable/c/9ca6a040f76c0b149293e430dabab446f3fc8ab7