net: lan743x: Fix memleak issue when GSO enabled
Summary
| CVE | CVE-2025-37909 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-05-20 16:15:27 UTC |
| Updated | 2026-07-14 13:17:34 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Fix memleak issue when GSO enabled Always map the `skb` to the LS descriptor. Previously skb was mapped to EXT descriptor when the number of fragments is zero with GSO enabled. Mapping the skb to EXT descriptor prevents it from being freed, leading to a memory leak |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-401
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a 093855ce90177488eac772de4eefbb909033ce5f git | Not specified |
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a 6c65ee5ad632eb8dcd3a91cf5dc99b22535f44d9 git | Not specified |
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a df993daa4c968b4b23078eacc248f6502ede8664 git | Not specified |
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a a0e0efbabbbe6a1859bc31bf65237ce91e124b9b git | Not specified |
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a dae1ce27ceaea7e1522025b15252e3cc52802622 git | Not specified |
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a 189b05f189cac9fd233ef04d31cb5078c4d09c39 git | Not specified |
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a f42c18e2f14c1b1fdd2a5250069a84bc854c398c git | Not specified |
| CNA | Linux | Linux | affected 23f0703c125be490f70501b6b24ed5645775c56a 2d52e2e38b85c8b7bc00dca55c2499f46f8c8198 git | Not specified |
| CNA | Linux | Linux | affected 4.17 | Not specified |
| CNA | Linux | Linux | unaffected 4.17 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.294 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.238 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.182 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.138 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.90 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.28 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.14.6 6.14.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.15 * original_commit_for_fix | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/093855ce90177488eac772de4eefbb909033ce5f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2025/08/msg00010.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List |
| git.kernel.org/stable/c/189b05f189cac9fd233ef04d31cb5078c4d09c39 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| cert-portal.siemens.com/productcert/html/ssa-019113.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/a0e0efbabbbe6a1859bc31bf65237ce91e124b9b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/dae1ce27ceaea7e1522025b15252e3cc52802622 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/6c65ee5ad632eb8dcd3a91cf5dc99b22535f44d9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/2d52e2e38b85c8b7bc00dca55c2499f46f8c8198 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/f42c18e2f14c1b1fdd2a5250069a84bc854c398c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/df993daa4c968b4b23078eacc248f6502ede8664 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2025/10/msg00007.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.