cbcvebase.
CVE-2025-37757
published 2025-05-01

CVE-2025-37757: In the Linux kernel, the following vulnerability has been resolved: tipc: fix memory leak in tipc_link_xmit In case the backlog transmit queue for…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.41%
34.2th percentile
In the Linux kernel, the following vulnerability has been resolved: tipc: fix memory leak in tipc_link_xmit In case the backlog transmit queue for system-importance messages is overloaded, tipc_link_xmit() returns -ENOBUFS but the skb list is not purged. This leads to memory leak and failure when a skb is allocated. This commit fixes this issue by purging the skb list before tipc_link_xmit() returns.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < 84895f5ce3829d9fc030e5ec2d8729da4c0c9d0884895f5ce3829d9fc030e5ec2d8729da4c0c9d08
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < d4d40e437adb376be16b3a12dd5c63f0fa768247d4d40e437adb376be16b3a12dd5c63f0fa768247
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < ed06675d3b8cd37120b447646d53f7cd3e6fcd63ed06675d3b8cd37120b447646d53f7cd3e6fcd63
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < 24e6280cdd7f8d01fc6b9b365fb800c2fb7ea9bb24e6280cdd7f8d01fc6b9b365fb800c2fb7ea9bb
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < 09c2dcda2c551bba30710c33f6ac678ae739538909c2dcda2c551bba30710c33f6ac678ae7395389
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < 7c5957f7905b4aede9d7a559d271438f3ca9e8527c5957f7905b4aede9d7a559d271438f3ca9e852
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < d0e02d3d27a0b4dcb13f954f537ca1dd8f282dcfd0e02d3d27a0b4dcb13f954f537ca1dd8f282dcf
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < a40cbfbb8f95c325430f017883da669b2aa927d4a40cbfbb8f95c325430f017883da669b2aa927d4
linuxlinux>= 365ad353c2564bba8835290061308ba825166b3a < 69ae94725f4fc9e75219d2d69022029c5b24bc9a69ae94725f4fc9e75219d2d69022029c5b24bc9a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.11 < 5.4.2935.4.293
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_msrc6.1MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.