#VU121975 Memory leak in Linux kernel - CVE-2025-71154
Published: January 23, 2026
Vulnerability identifier: #VU121975
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-71154
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the async_set_registers() function in drivers/net/usb/rtl8150.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/12cab1191d9890097171156d06bfa8d31f1e39c8
- https://git.kernel.org/stable/c/151403e903840c9cf06754097b6732c14f26c532
- https://git.kernel.org/stable/c/2f966186b99550e3c665dbfb87b8314e30acea02
- https://git.kernel.org/stable/c/4bd4ea3eb326608ffc296db12c105f92dc2f2190
- https://git.kernel.org/stable/c/6492ad6439ff1a479fc94dc6052df3628faed8b6
- https://git.kernel.org/stable/c/a4e2442d3c48355a84463342f397134f149936d7
- https://git.kernel.org/stable/c/db2244c580540306d60ce783ed340190720cd429