In the Linux kernel, the following vulnerability has been resolved:
mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write
memcg_path_store() assigns a newly allocated memory buffer to
filter->memcg_path, without deallocating the previously allocated and
assigned memory buffer. As a result, users can leak kernel memory by
continuously writing a data to memcg_path DAMOS sysfs file. Fix the leak
by deallocating the previously set memory buffer.
References
Configurations
Configuration 1 (hide)
|
History
19 Nov 2025, 20:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/490a43d07f1663d827e802720d30cbc0494e4f81 - Patch | |
| References | () https://git.kernel.org/stable/c/4a158ac0538dd5695eeaa00aa0720d711f3e4ef1 - Patch | |
| References | () https://git.kernel.org/stable/c/4f489fe6afb395dbc79840efa3c05440b760d883 - Patch | |
| References | () https://git.kernel.org/stable/c/c5d5b0047b0c0f304608f3824139f7bd34c48413 - Patch | |
| CWE | CWE-401 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| First Time |
Linux
Linux linux Kernel |
|
| CPE | cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
10 Jul 2025, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
09 Jul 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-09 11:15
Updated : 2025-11-19 20:52
NVD link : CVE-2025-38258
Mitre link : CVE-2025-38258
CVE.ORG link : CVE-2025-38258
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
