We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-37955

virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable()



Description

In the Linux kernel, the following vulnerability has been resolved: virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable() The selftests added to our CI by Bui Quang Minh recently reveals that there is a mem leak on the error path of virtnet_xsk_pool_enable(): unreferenced object 0xffff88800a68a000 (size 2048): comm "xdp_helper", pid 318, jiffies 4294692778 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc 0): __kvmalloc_node_noprof+0x402/0x570 virtnet_xsk_pool_enable+0x293/0x6a0 (drivers/net/virtio_net.c:5882) xp_assign_dev+0x369/0x670 (net/xdp/xsk_buff_pool.c:226) xsk_bind+0x6a5/0x1ae0 __sys_bind+0x15e/0x230 __x64_sys_bind+0x72/0xb0 do_syscall_64+0xc1/0x1d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Reserved 2025-04-16 | Published 2025-05-20 | Updated 2025-05-26 | Assigner Linux

Product status

Default status
unaffected

e9f3962441c0a4d6f16c656e6c8aa02a3ccdd568 before 94a6f6c204abb2b2dcd2ce287536cc924469cfb5
affected

e9f3962441c0a4d6f16c656e6c8aa02a3ccdd568 before ba6917810bb4a5a32661fa941717399052b3f0d9
affected

e9f3962441c0a4d6f16c656e6c8aa02a3ccdd568 before 4397684a292a71fbc1e815c3e283f7490ddce5ae
affected

Default status
affected

6.11
affected

Any version before 6.11
unaffected

6.12.29
unaffected

6.14.7
unaffected

6.15
unaffected

References

git.kernel.org/...c/94a6f6c204abb2b2dcd2ce287536cc924469cfb5

git.kernel.org/...c/ba6917810bb4a5a32661fa941717399052b3f0d9

git.kernel.org/...c/4397684a292a71fbc1e815c3e283f7490ddce5ae

cve.org (CVE-2025-37955)

nvd.nist.gov (CVE-2025-37955)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-37955

Support options

Helpdesk Chat, Email, Knowledgebase