#VU103510 Memory leak in Linux kernel - CVE-2025-21683


Vulnerability identifier: #VU103510

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21683

CWE-ID: CWE-401

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the BPF_CALL_4() function in net/core/filter.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/0ab52a8ca6e156a64c51b5e7456cac9a0ebfd9bf
https://git.kernel.org/stable/c/b02e70be498b138e9c21701c2f33f4018ca7cd5e
https://git.kernel.org/stable/c/b3af60928ab9129befa65e6df0310d27300942bf
https://git.kernel.org/stable/c/bb36838dac7bb334a3f3d7eb29875593ec9473fc
https://git.kernel.org/stable/c/cccd51dd22574216e64e5d205489e634f86999f3
https://git.kernel.org/stable/c/d0a3b3d1176d39218b8edb2a2d03164942ab9ccd


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability