cbcvebase.
CVE-2025-37908
published 2025-05-20

CVE-2025-37908: In the Linux kernel, the following vulnerability has been resolved: mm, slab: clean up slab->obj_exts always When memory allocation profiling is disabled at…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: mm, slab: clean up slab->obj_exts always When memory allocation profiling is disabled at runtime or due to an error, shutdown_mem_profiling() is called: slab->obj_exts which previously allocated remains. It won't be cleared by unaccount_slab() because of mem_alloc_profiling_enabled() not true. It's incorrect, slab->obj_exts should always be cleaned up in unaccount_slab() to avoid following error: [...]BUG: Bad page state in process... .. [...]page dumped because: page still charged to cgroup [[email protected]: fold need_slab_obj_ext() into its only user]

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.29-1 (forky)linux 6.12.29-1 (forky)
linuxlinux
linuxlinux>= 21c690a349baab895dc68ab70d291e1598d7109d < dab2a13059a475b6392550f882276e170fe2fcffdab2a13059a475b6392550f882276e170fe2fcff
linuxlinux>= 21c690a349baab895dc68ab70d291e1598d7109d < 01db0e1a48345aa1937f3bdfc7c7108d03ebcf7e01db0e1a48345aa1937f3bdfc7c7108d03ebcf7e
linuxlinux>= 21c690a349baab895dc68ab70d291e1598d7109d < be8250786ca94952a19ce87f98ad9906448bc9efbe8250786ca94952a19ce87f98ad9906448bc9ef
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.14.0-24.246.14.0-24.24
linuxlinux_kernel>= 6.10 < 6.12.286.12.28
linuxlinux_kernel>= 6.13 < 6.14.66.14.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.