Use of Uninitialized Variable in slab - CVE-2025-55159
Published: August 26, 2025
Vulnerability identifier: #VU114431
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55159
CWE-ID: CWE-457
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to usage of uninitialized memory within the get_disjoint_mut() function. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
slab
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Fedora
Development Tools Module
Basesystem Module
SAP Applications Module
openSUSE Leap
openEuler
rust-keylime
rust-keylime-debuginfo
sccache-debuginfo
sccache
sccache-debugsource
rust-slab
python3-Cerberus
wicked2nm-debuginfo
wicked2nm-debugsource
wicked2nm
SLES16-SAP_Migration
SLES16-Migration
suse-migration-sle16-activation
python3-migration
suse-migration-pre-checks
gnome-tour
gnome-tour-debuginfo
gnome-tour-debugsource
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Fedora
Development Tools Module
Basesystem Module
SAP Applications Module
openSUSE Leap
openEuler
rust-keylime
rust-keylime-debuginfo
sccache-debuginfo
sccache
sccache-debugsource
rust-slab
python3-Cerberus
wicked2nm-debuginfo
wicked2nm-debugsource
wicked2nm
SLES16-SAP_Migration
SLES16-Migration
suse-migration-sle16-activation
python3-migration
suse-migration-pre-checks
gnome-tour
gnome-tour-debuginfo
gnome-tour-debugsource
How to mitigate CVE-2025-55159
Install updates from vendor's website.
slab - update to 0.4.11
rust-keylime - addressed in versions 0.2.8+12-150400.3.8.1, 0.2.8+12-150400.3.10.1, 0.2.8+12-150500.3.8.1
rust-keylime-debuginfo - addressed in versions 0.2.8+12-150400.3.8.1, 0.2.8+12-150400.3.10.1, 0.2.8+12-150500.3.8.1
sccache-debuginfo - addressed in versions 0.4.2~4-150400.3.9.1, 0.4.2~4-150600.10.6.1
sccache - addressed in versions 0.4.2~4-150400.3.9.1, 0.4.2~4-150600.10.6.1
sccache-debugsource - update to 0.4.2~4-150400.3.9.1
rust-slab - addressed in versions 0.4.11-1.el9, 0.4.11-1.el10_0, 0.4.11-1.el10_1, 0.4.11-1.fc41, 0.4.11-1.fc42
python3-Cerberus - update to 1.3.2-150700.20.2.10
wicked2nm-debuginfo - update to 1.4.0-150700.15.7.2
wicked2nm-debugsource - update to 1.4.0-150700.15.7.2
wicked2nm - update to 1.4.0-150700.15.7.2
SLES16-SAP_Migration - update to 2.1.26-15.14.4
SLES16-Migration - update to 2.1.26-15.22.4
suse-migration-sle16-activation - update to 2.1.26-150700.15.9.1
python3-migration - update to 2.1.26-150700.16.12.1
suse-migration-pre-checks - update to 2.1.26-150700.16.12.1
gnome-tour - addressed in versions 3.38.0-3, 44.0-2, 44.0-3
gnome-tour-debuginfo - addressed in versions 44.0-2, 44.0-3
gnome-tour-debugsource - addressed in versions 44.0-2, 44.0-3
rust-keylime - addressed in versions 0.2.8+12-150400.3.8.1, 0.2.8+12-150400.3.10.1, 0.2.8+12-150500.3.8.1
rust-keylime-debuginfo - addressed in versions 0.2.8+12-150400.3.8.1, 0.2.8+12-150400.3.10.1, 0.2.8+12-150500.3.8.1
sccache-debuginfo - addressed in versions 0.4.2~4-150400.3.9.1, 0.4.2~4-150600.10.6.1
sccache - addressed in versions 0.4.2~4-150400.3.9.1, 0.4.2~4-150600.10.6.1
sccache-debugsource - update to 0.4.2~4-150400.3.9.1
rust-slab - addressed in versions 0.4.11-1.el9, 0.4.11-1.el10_0, 0.4.11-1.el10_1, 0.4.11-1.fc41, 0.4.11-1.fc42
python3-Cerberus - update to 1.3.2-150700.20.2.10
wicked2nm-debuginfo - update to 1.4.0-150700.15.7.2
wicked2nm-debugsource - update to 1.4.0-150700.15.7.2
wicked2nm - update to 1.4.0-150700.15.7.2
SLES16-SAP_Migration - update to 2.1.26-15.14.4
SLES16-Migration - update to 2.1.26-15.22.4
suse-migration-sle16-activation - update to 2.1.26-150700.15.9.1
python3-migration - update to 2.1.26-150700.16.12.1
suse-migration-pre-checks - update to 2.1.26-150700.16.12.1
gnome-tour - addressed in versions 3.38.0-3, 44.0-2, 44.0-3
gnome-tour-debuginfo - addressed in versions 44.0-2, 44.0-3
gnome-tour-debugsource - addressed in versions 44.0-2, 44.0-3
External References
Related Security Bulletins
- Denial of service in Tokio slab
- Fedora EPEL 10.1 update for rust-slab
- Fedora EPEL 9 update for rust-slab
- Fedora EPEL 10.0 update for rust-slab
- Fedora 41 update for rust-slab
- Fedora 42 update for rust-slab
- SUSE update for rust-keylime
- SUSE update for rust-keylime
- SUSE update for rust-keylime
- SUSE update for sccache
- SUSE update for sccache
- SUSE update for Recommended update for suse-migration-sle16-activation, SLES16-Migration, SLES16-SAP_Migration, suse-migration-services, suse-migration-rpm, wicked2nm, image-janitor
- openEuler 24.03 LTS SP3 update for gnome-tour
- openEuler 24.03 LTS SP1 update for gnome-tour
- openEuler 22.03 LTS SP4 update for gnome-tour
- openEuler 24.03 LTS SP4 update for gnome-tour