Device Reference Count Leak in Linux Kernel
CVE-2025-38542

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 August 2025

What is CVE-2025-38542?

A vulnerability exists in the Linux Kernel's appletalk implementation, where an outdated device reference is not properly released during the update of a route entry in the atrtr_create() function. This oversight can lead to a device reference count leak, which can impact system stability and resource management. The vulnerability has been addressed by implementing a fix that ensures the old device reference is released before assigning the new one, thereby preventing potential memory resource exhaustion.

Affected Version(s)

Linux c7f905f0f6d49ed8c1aa4566c31f0383a0ba0c9d

Linux c7f905f0f6d49ed8c1aa4566c31f0383a0ba0c9d

Linux c7f905f0f6d49ed8c1aa4566c31f0383a0ba0c9d

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.