CVE-2025-21981
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2025
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ice: fix memory leak in aRFS after reset<br />
<br />
Fix aRFS (accelerated Receive Flow Steering) structures memory leak by<br />
adding a checker to verify if aRFS memory is already allocated while<br />
configuring VSI. aRFS objects are allocated in two cases:<br />
- as part of VSI initialization (at probe), and<br />
- as part of reset handling<br />
<br />
However, VSI reconfiguration executed during reset involves memory<br />
allocation one more time, without prior releasing already allocated<br />
resources. This led to the memory leak with the following signature:<br />
<br />
[root@os-delivery ~]# cat /sys/kernel/debug/kmemleak<br />
unreferenced object 0xff3c1ca7252e6000 (size 8192):<br />
comm "kworker/0:0", pid 8, jiffies 4296833052<br />
hex dump (first 32 bytes):<br />
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................<br />
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................<br />
backtrace (crc 0):<br />
[] __kmalloc_cache_noprof+0x275/0x340<br />
[] ice_init_arfs+0x3a/0xe0 [ice]<br />
[] ice_vsi_cfg_def+0x607/0x850 [ice]<br />
[] ice_vsi_setup+0x5b/0x130 [ice]<br />
[] ice_init+0x1c1/0x460 [ice]<br />
[] ice_probe+0x2af/0x520 [ice]<br />
[] local_pci_probe+0x43/0xa0<br />
[] work_for_cpu_fn+0x13/0x20<br />
[] process_one_work+0x179/0x390<br />
[] worker_thread+0x239/0x340<br />
[] kthread+0xcc/0x100<br />
[] ret_from_fork+0x2d/0x50<br />
[] ret_from_fork_asm+0x1a/0x30<br />
...
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.8 (including) | 6.1.132 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.84 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.20 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.13.8 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.14:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.14:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.14:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.14:rc6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/23d97f18901ef5e4e264e3b1777fe65c760186b5
- https://git.kernel.org/stable/c/3b27e6e10a32589fcd293b8933ab6de9387a460e
- https://git.kernel.org/stable/c/5d30d256661fc11b6e73fac6c3783a702e1006a3
- https://git.kernel.org/stable/c/78f3d64b30210c0e521c59357431aca14024cb79
- https://git.kernel.org/stable/c/e6902101f34f098af59b0d1d8cf90c4124c02c6a
- https://git.kernel.org/stable/c/ef2bc94059836a115430a6ad9d2838b0b34dc8f5
- https://git.kernel.org/stable/c/fcbacc47d16306c87ad1b820b7a575f6e9eae58b
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html



