CVE-2025-37744 — Missing Release of Memory after Effective Lifetime in Linux
Severity
5.5MEDIUMNVD
OSV3.2
EPSS
0.1%
top 77.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix memory leak in ath12k_pci_remove()
Kmemleak reported this error:
unreferenced object 0xffff1c165cec3060 (size 32):
comm "insmod", pid 560, jiffies 4296964570 (age 235.596s)
backtrace:
[] __kmem_cache_alloc_node+0x1f4/0x2c0
[] kmalloc_trace+0x40/0x88
[] _request_firmware+0xb8/0x608
[] firmware_request_nowarn+0x50/0x80
[] local_pci_probe+0x48/0xd0
[] pci_device_probe+0xb4/0x200
[] really_probe+0x150/0x2c0
The…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages14 packages
▶CVEListV5linux/linuxfc38e9339c47d704934bc74e55c331f0d2d88583 — 52e3132e62c31b5ade43dc4495fa81175e6e8398+2