CNNVD-202510-221 Information

CNNVD ID

CNNVD-202510-221

CVE-2025-39913

  • CNNVD Published: 2025-10-01

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于tcp_bpf_send_verdict分配psock->cork失败时未调用sk_msg_free,可能导致内存泄漏。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. Linux kelnel has a security loophole, which stems from the failure of tcp bpf send verdict allocated psock->cork without calling ssk msg free, which could cause a memory leak.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-10-01

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/05366527f44cf4b884f3d9462ae8009be9665856 https://git.kernel.org/stable/c/08f58d10f5abf11d297cc910754922498c921f91 https://git.kernel.org/stable/c/539920180c55f5e13a2488a2339f94e6b8cb69e0 https://git.kernel.org/stable/c/66bcb04a441fbf15d66834b7e3eefb313dd750c8 https://git.kernel.org/stable/c/7429b8b9bfbc276fd304fbaebc405f46b421fedf https://git.kernel.org/stable/c/9c2a6456bdf9794474460d885c359b6c4522d6e3 https://git.kernel.org/stable/c/a3967baad4d533dc254c31e0d221e51c8d223d58 https://git.kernel.org/stable/c/de89e58368f8f07df005ecc1c86ad94898a999f2

Patch

https://www.kernel.org/

Share on: