cbcvebase.
CVE-2025-38079
published 2025-06-18

CVE-2025-38079: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type algif_hash with MSG_MORE flag set and crypto_ahash_import fails, sk2 is freed. However, it is also freed in af_alg_release, leading to slab-use-after-free error.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < 5bff312b59b3f2a54ff504e4f4e47272b64f36335bff312b59b3f2a54ff504e4f4e47272b64f3633
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < bf7bba75b91539e93615f560893a599c1e1c98bfbf7bba75b91539e93615f560893a599c1e1c98bf
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < c3059d58f79fdfb2201249c2741514e34562b547c3059d58f79fdfb2201249c2741514e34562b547
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < f0f3d09f53534ea385d55ced408f2b67059b16e4f0f3d09f53534ea385d55ced408f2b67059b16e4
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < 134daaba93193df9e988524b5cd2f52d15eb1993134daaba93193df9e988524b5cd2f52d15eb1993
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < 2f45a8d64fb4ed4830a4b3273834ecd6ca5048962f45a8d64fb4ed4830a4b3273834ecd6ca504896
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < 0346f4b742345d1c733c977f3a7aef5a6419a9670346f4b742345d1c733c977f3a7aef5a6419a967
linuxlinux>= fe869cdb89c95d060c77eea20204d6c91f233b53 < b2df03ed4052e97126267e8c13ad4204ea6ba9b6b2df03ed4052e97126267e8c13ad4204ea6ba9b6
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 5.15.0-152.1625.15.0-152.162
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc7.0HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.