PT-2025-20522 · Linux+4 · Linux Kernel+4
Published
2025-04-15
·
Updated
2026-04-20
·
CVE-2025-37872
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory leak issue has been identified in the Linux kernel, specifically in the txgbe probe() function. The leak occurs when the txgbe sw init() function is called, allocating memory for the
rss key variable, but this memory is not freed in the error path. This issue could potentially lead to a double free of the rss key when the mac table allocation fails in the wx sw init() function. The estimated number of potentially affected devices worldwide is not available.Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for the memory leak in the txgbe probe() error path.
As a temporary workaround, consider disabling the
txgbe probe() function until a patch is available.
Restrict access to the vulnerable txgbe sw init() function to minimize the risk of exploitation.
Avoid using the rss key variable in the affected API endpoint until the issue is resolved.Exploit
Fix
Memory Leak
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu