#VU114965 Improper resource shutdown or release in Linux kernel - CVE-2025-39695
Published: September 8, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to properly release resources within the rxe_qp_init_req() function in drivers/infiniband/sw/rxe/rxe_qp.c, within the rxe_prepare(), rxe_send(), rxe_loopback() and rxe_init_packet() functions in drivers/infiniband/sw/rxe/rxe_net.c. A local user can perform a denial of service (DoS) attack.