PT-2025-33587 · Linux+4 · Linux Kernel+4
Published
2025-07-08
·
Updated
2026-04-20
·
CVE-2025-38544
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A flaw exists in the Linux kernel’s rxrpc subsystem related to preallocation of incoming calls when using AF RXRPC for server functionality. The issue arises from a collision during preallocation, where attempts to preallocate a call with an already in-use call ID do not correctly handle error conditions. This can lead to assertions being triggered within the
rxrpc cleanup call() function because the call is not properly marked as complete or released.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Allocation of Resources Without Limits
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu