PT-2025-38559 · Linux+4 · Linux Kernel+4

Published

2025-04-16

·

Updated

2026-05-07

·

CVE-2025-39852

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak exists in the TCP-AO failure handling for IPv6 within the Linux kernel. Specifically, when tcp ao copy all matching() fails in tcp v6 syn recv sock(), the function exits without properly freeing allocated memory, leading to a memory leak. This occurs because inet csk prepare forced close() and tcp done() are not called upon error, which are necessary for correct memory deallocation. The issue is addressed by ensuring consistent error handling between tcp v4 syn recv sock() and tcp v6 syn recv sock().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2025-13445
CVE-2025-39852
DSA-6008-1
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu