PT-2025-38559 · Linux+4 · Linux Kernel+4
Published
2025-04-16
·
Updated
2026-05-07
·
CVE-2025-39852
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory leak exists in the TCP-AO failure handling for IPv6 within the Linux kernel. Specifically, when
tcp ao copy all matching() fails in tcp v6 syn recv sock(), the function exits without properly freeing allocated memory, leading to a memory leak. This occurs because inet csk prepare forced close() and tcp done() are not called upon error, which are necessary for correct memory deallocation. The issue is addressed by ensuring consistent error handling between tcp v4 syn recv sock() and tcp v6 syn recv sock().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu