SB20250502121 - Memory leak in Linux kernel
Published: May 2, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-37747)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the exclusive_event_installable(), _free_event(), perf_remove_from_owner(), list_del(), perf_pending_task(), __perf_event_overflow(), perf_event_alloc(), perf_event_exit_event() and perf_free_event() functions in kernel/events/core.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1267bd38f161c1a27d9b722de017027167a225a0
- https://git.kernel.org/stable/c/56799bc035658738f362acec3e7647bb84e68933
- https://git.kernel.org/stable/c/665b87b8f8b3aeb49083ef3b65c4953e7753fc12
- https://git.kernel.org/stable/c/fa1827fa968c0674e9b6fca223fa9fb4da4493eb
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.24