PT-2025-8904 · Linux+7 · Linux Kernel+7

Published

2025-02-03

·

Updated

2026-05-26

·

CVE-2025-21792

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the version containing the fix for the refcount leak in ax25 release()
Description A refcount leak occurs in the Linux kernel when an AX25 device is bound to a socket by setting the SO BINDTODEVICE socket option. This happens because the refcounts are not incremented when the device is bound using this method, unlike when using ax25 bind(). The issue leads to a memory leak warning reported by Syzkaller. The problem arises from the incorrect implementation of ax25 setsockopt(), which fails to increment refcounts for the new device bound and decrement refcounts for the old unbound device.
Recommendations For Linux kernel versions prior to the fixed version, apply the patch that fixes the implementation of ax25 setsockopt() by adding the necessary increment and decrement of refcounts for the bound and unbound devices. As a temporary workaround, consider avoiding the use of the SO BINDTODEVICE socket option to bind AX25 devices to sockets until the issue is resolved.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
AZL-57819
AZL-57965
BDU:2025-12044
CVE-2025-21792
DLA-4102-1
OESA-2025-1446
OESA-2025-1450
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:20343-1
SUSE-SU-2025:20344-1
SUSE-SU-2025:20354-1
SUSE-SU-2025:20355-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7703-1
USN-7703-2
USN-7703-3
USN-7703-4
USN-7719-1
USN-7737-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu