Use of Uninitialized Variable in slab - CVE-2025-55159

 

Use of Uninitialized Variable in slab - CVE-2025-55159

Published: August 26, 2025


Vulnerability identifier: #VU114431
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55159
CWE-ID: CWE-457
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to usage of uninitialized memory within the get_disjoint_mut() function. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

slab
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Fedora
Development Tools Module
Basesystem Module
SAP Applications Module
openSUSE Leap
openEuler
rust-keylime
rust-keylime-debuginfo
sccache-debuginfo
sccache
sccache-debugsource
rust-slab
python3-Cerberus
wicked2nm-debuginfo
wicked2nm-debugsource
wicked2nm
SLES16-SAP_Migration
SLES16-Migration
suse-migration-sle16-activation
python3-migration
suse-migration-pre-checks
gnome-tour
gnome-tour-debuginfo
gnome-tour-debugsource

How to mitigate CVE-2025-55159

Install updates from vendor's website.

slab - update to 0.4.11
rust-keylime - addressed in versions 0.2.8+12-150400.3.8.1, 0.2.8+12-150400.3.10.1, 0.2.8+12-150500.3.8.1
rust-keylime-debuginfo - addressed in versions 0.2.8+12-150400.3.8.1, 0.2.8+12-150400.3.10.1, 0.2.8+12-150500.3.8.1
sccache-debuginfo - addressed in versions 0.4.2~4-150400.3.9.1, 0.4.2~4-150600.10.6.1
sccache - addressed in versions 0.4.2~4-150400.3.9.1, 0.4.2~4-150600.10.6.1
sccache-debugsource - update to 0.4.2~4-150400.3.9.1
rust-slab - addressed in versions 0.4.11-1.el9, 0.4.11-1.el10_0, 0.4.11-1.el10_1, 0.4.11-1.fc41, 0.4.11-1.fc42
python3-Cerberus - update to 1.3.2-150700.20.2.10
wicked2nm-debuginfo - update to 1.4.0-150700.15.7.2
wicked2nm-debugsource - update to 1.4.0-150700.15.7.2
wicked2nm - update to 1.4.0-150700.15.7.2
SLES16-SAP_Migration - update to 2.1.26-15.14.4
SLES16-Migration - update to 2.1.26-15.22.4
suse-migration-sle16-activation - update to 2.1.26-150700.15.9.1
python3-migration - update to 2.1.26-150700.16.12.1
suse-migration-pre-checks - update to 2.1.26-150700.16.12.1
gnome-tour - addressed in versions 3.38.0-3, 44.0-2, 44.0-3
gnome-tour-debuginfo - addressed in versions 44.0-2, 44.0-3
gnome-tour-debugsource - addressed in versions 44.0-2, 44.0-3

External References

Related Security Bulletins