PT-2025-16712 · Linux+5 · Linux Kernel+5

Published

2025-03-13

·

Updated

2026-05-26

·

CVE-2025-22072

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns a problem with gang directory lifetimes in the Linux kernel. Specifically, the creation of a gang returns an opened gang directory, which should be removed when closed. However, if a context belonging to that gang is created and kept alive until the gang is closed, the removal fails, resulting in a leak. The initial fix for this problem was incorrect, leading to issues with the dentry of the gang directory not being pinned and the rmdir on close being gone. This caused problems, including an unbalanced dput() when open failed and a link count on the root directory not being undone when the gang was destroyed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2025-12039
CVE-2025-22072
DLA-4193-1
DSA-5907-1
ECHO-F963-DB66-0206
MGASA-2025-0142
MGASA-2025-0146
OESA-2025-1463
OESA-2025-1464
USN-7594-1
USN-7594-2
USN-7594-3
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7835-1
USN-7835-2
USN-7835-3
USN-7835-4
USN-7835-5
USN-7835-6
USN-7887-1
USN-7887-2
USN-7940-1
USN-7940-2

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu