SB2025042234 - Memory leak in Linux kernel ipv4
Published: April 22, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-22058)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the udp_skb_has_head_state(), udp_rmem_release(), EXPORT_SYMBOL_GPL() and first_packet_length() functions in net/ipv4/udp.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3836029448e76c1e6f77cc5fe0adc09b018b5fa8
- https://git.kernel.org/stable/c/9122fec396950cc866137af7154b1d0d989be52e
- https://git.kernel.org/stable/c/a116b271bf3cb72c8155b6b7f39083c1b80dcd00
- https://git.kernel.org/stable/c/aeef6456692c6f11ae53d278df64f1316a2a405a
- https://git.kernel.org/stable/c/c4bac6c398118fba79e32b1cd01db22dbfe29fbf
- https://git.kernel.org/stable/c/df207de9d9e7a4d92f8567e2c539d9c8c12fd99d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.134
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.23
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.87