#VU115361 Memory leak in Linux kernel - CVE-2025-39737
Published: September 16, 2025
Vulnerability identifier: #VU115361
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-39737
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the __kmemleak_do_cleanup() function in mm/kmemleak.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/1ef72a7fedc5bca70e8cc980985790de10d407aa
- https://git.kernel.org/stable/c/8d2d22a55ffe35c38e69795468a7addd1a80e9ce
- https://git.kernel.org/stable/c/926092268efdf1ed7b55cf486356c74a9e7710d1
- https://git.kernel.org/stable/c/9b80430c194e4a114dc663c1025d56b4f3d0153d
- https://git.kernel.org/stable/c/9f1f4e95031f84867c5821540466d62f88dab8ca
- https://git.kernel.org/stable/c/a04de4c40aab9b338dfa989cf4aec70fd187eeb2
- https://git.kernel.org/stable/c/d1534ae23c2b6be350c8ab060803fbf6e9682adc
- https://git.kernel.org/stable/c/e21a3ddd58733ce31afcb1e5dc3cb80a4b5bc29b
- https://git.kernel.org/stable/c/f014c10d190b92aad366e56b445daffcd1c075e4