Resource management error in Linux kernel - CVE-2025-38525
Published: August 18, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the rxrpc_lookup_peer_rcu(), rxrpc_init_peer() and rxrpc_create_peer() functions in net/rxrpc/peer_object.c, within the rxrpc_new_incoming_call() function in net/rxrpc/call_accept.c. A local user can perform a denial of service (DoS) attack.
Affected software
Debian Linux
Ubuntu
linux (Debian package)
linux (Ubuntu package)
linux-oem-6.14 (Ubuntu package)
linux-realtime-6.14 (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws-6.14 (Ubuntu package)
linux-gcp-6.14 (Ubuntu package)
How to mitigate CVE-2025-38525
linux (Ubuntu package) - addressed in versions 6.14.0-36.36, 6.14.0-36.36~24.04.1, 6.14.0-1016.16~24.04.1, 6.14.0-1017.17, 6.14.0-1020.21
linux-oem-6.14 (Ubuntu package) - update to 6.14.0-1016.16
linux-realtime-6.14 (Ubuntu package) - update to 6.14.0-1016.16~24.04.1
linux-azure (Ubuntu package) - addressed in versions 6.14.0-1017.17, 6.14.0-1017.17~24.04.1
linux-aws-6.14 (Ubuntu package) - update to 6.14.0-1017.17~24.04.1
linux-gcp-6.14 (Ubuntu package) - addressed in versions 6.14.0-1018.18, 6.14.0-1020.21~24.04.1