#VU111690 Improper resource shutdown or release in Linux kernel - CVE-2025-38042
Published: June 20, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to properly release resources within the prueth_reset_rx_chan() function in drivers/net/ethernet/ti/icssg/icssg_common.c, within the am65_cpsw_destroy_rxq() and am65_cpsw_nuss_register_ndevs() functions in drivers/net/ethernet/ti/am65-cpsw-nuss.c, within the k3_udma_chan_dev_release(), k3_udma_glue_request_rx_chn_priv(), k3_udma_glue_request_remote_rx_chn_common(), EXPORT_SYMBOL_GPL() and k3_udma_glue_reset_rx_chn() functions in drivers/dma/ti/k3-udma-glue.c. A local user can perform a denial of service (DoS) attack.