Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-39834— net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow

AI Predicted 3.3 Difficulty: Easy EPSS 0.12% · P2

Possible ATT&CK Techniques 1AI

T1496 · Resource Hijacking

Affected Version Matrix 6

VendorProductVersion RangeStatus
LinuxLinux504e536d90104c850731840d3fbc95acf251f11b< 051fd8576a2e4e95d5870c5c9f8679c5b16882e4affected
504e536d90104c850731840d3fbc95acf251f11b< a630f83592cdad1253523a1b760cfe78fef6cd9caffected
6.12affected
< 6.12unaffected
6.16.5≤ 6.16.*unaffected
6.17≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-39834

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow When an invalid stc_type is provided, the function allocates memory for shared_stc but jumps to unlock_and_out without freeing it, causing a memory leak. Fix by jumping to free_shared_stc label instead to ensure proper cleanup.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于错误处理流程中未释放内存,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 504e536d90104c850731840d3fbc95acf251f11b ~ 051fd8576a2e4e95d5870c5c9f8679c5b16882e4 -
LinuxLinux 6.12 -

II. Public POCs for CVE-2025-39834

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-39834

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-16 · 115 CVEs total

CVE-2025-398278.8 HIGHnet: rose: include node references in rose_neigh refcount
CVE-2025-398068.8 HIGHHID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
CVE-2025-398268.8 HIGHnet: rose: convert 'use' field to refcount_t
CVE-2025-398098.4 HIGHHID: intel-thc-hid: intel-quicki2c: Fix ACPI dsd ICRS/ISUB length
CVE-2025-398257.8 HIGHsmb: client: fix race with concurrent opens in rename(2)
CVE-2025-398107.8 HIGHbnxt_en: Fix memory corruption when FW resources change during ifdown
CVE-2025-398367.8 HIGHefi: stmm: Fix incorrect buffer allocation method
CVE-2025-398157.8 HIGHRISC-V: KVM: fix stack overrun when loading vlenb
CVE-2025-398187.8 HIGHHID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save
CVE-2025-398217.8 HIGHperf: Avoid undefined behavior from stopping/starting inactive events
CVE-2025-398177.1 HIGHefivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
CVE-2022-50351cifs: Fix xid leak in cifs_create()
CVE-2022-50349misc: tifm: fix possible memory leak in tifm_7xx1_switch_media()
CVE-2023-53304netfilter: nft_set_rbtree: fix overlap expiration walk
CVE-2022-50352net: hns: fix possible memory leak in hnae_ae_register()
CVE-2022-50344ext4: fix null-ptr-deref in ext4_write_info
CVE-2022-50350scsi: target: iscsi: Fix a race condition between login_work and the login thread
CVE-2022-50348nfsd: Fix a memory leak in an error handling path
CVE-2022-50347mmc: rtsx_usb_sdmmc: fix return value check of mmc_add_host()
CVE-2022-50343rapidio: fix possible name leaks when rio_add_device() fails

Showing top 20 of 115 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-39834

No comments yet


Leave a comment