SB20250520123 - Memory leak in Linux kernel ethernet microchip driver
Published: May 20, 2025 Updated: May 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-37909)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the lan743x_tx_frame_add_lso(), lan743x_tx_frame_add_fragment() and lan743x_tx_frame_end() functions in drivers/net/ethernet/microchip/lan743x_main.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/189b05f189cac9fd233ef04d31cb5078c4d09c39
- https://git.kernel.org/stable/c/2d52e2e38b85c8b7bc00dca55c2499f46f8c8198
- https://git.kernel.org/stable/c/a0e0efbabbbe6a1859bc31bf65237ce91e124b9b
- https://git.kernel.org/stable/c/dae1ce27ceaea7e1522025b15252e3cc52802622
- https://git.kernel.org/stable/c/df993daa4c968b4b23078eacc248f6502ede8664
- https://git.kernel.org/stable/c/f42c18e2f14c1b1fdd2a5250069a84bc854c398c
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.6