PT-2025-20522 · Linux+4 · Linux Kernel+4

Published

2025-04-15

·

Updated

2026-04-20

·

CVE-2025-37872

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the Linux kernel, specifically in the txgbe probe() function. The leak occurs when the txgbe sw init() function is called, allocating memory for the rss key variable, but this memory is not freed in the error path. This issue could potentially lead to a double free of the rss key when the mac table allocation fails in the wx sw init() function. The estimated number of potentially affected devices worldwide is not available.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the memory leak in the txgbe probe() error path. As a temporary workaround, consider disabling the txgbe probe() function until a patch is available. Restrict access to the vulnerable txgbe sw init() function to minimize the risk of exploitation. Avoid using the rss key variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

Memory Leak

Double Free

Weakness Enumeration

Related Identifiers

BDU:2025-12060
CVE-2025-37872
USN-7594-1
USN-7594-2
USN-7594-3
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu