cbcvebase.
CVE-2025-21788
published 2025-02-27

CVE-2025-21788: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases If the XDP program doesn't…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.48%
38.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases If the XDP program doesn't result in XDP_PASS then we leak the memory allocated by am65_cpsw_build_skb(). It is pointless to allocate SKB memory before running the XDP program as we would be wasting CPU cycles for cases other than XDP_PASS. Move the SKB allocation after evaluating the XDP program result. This fixes the memleak. A performance boost is seen for XDP_DROP test. XDP_DROP test: Before: 460256 rx/s 0 err/s After: 784130 rx/s 0 err/s

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.16-1 (forky)linux 6.12.16-1 (forky)
linuxlinux
linuxlinux>= 8acacc40f7337527ff84cd901ed2ef0a2b95b2b6 < 1bba1d042107167164a0ae3a843fdf650ab005d71bba1d042107167164a0ae3a843fdf650ab005d7
linuxlinux>= 8acacc40f7337527ff84cd901ed2ef0a2b95b2b6 < dc11f049612b9d926aca2e55f8dc9d82850d0da3dc11f049612b9d926aca2e55f8dc9d82850d0da3
linuxlinux>= 8acacc40f7337527ff84cd901ed2ef0a2b95b2b6 < 5db843258de1e4e6b1ef1cbd1797923c9e3de5485db843258de1e4e6b1ef1cbd1797923c9e3de548
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 6.10 < 6.12.166.12.16
linuxlinux_kernel>= 6.13 < 6.13.46.13.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.