{"id":"DEBIAN-CVE-2025-37955","details":"In the Linux kernel, the following vulnerability has been resolved:  virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable()  The selftests added to our CI by Bui Quang Minh recently reveals that there is a mem leak on the error path of virtnet_xsk_pool_enable():  unreferenced object 0xffff88800a68a000 (size 2048):   comm \"xdp_helper\", pid 318, jiffies 4294692778   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................   backtrace (crc 0):     __kvmalloc_node_noprof+0x402/0x570     virtnet_xsk_pool_enable+0x293/0x6a0 (drivers/net/virtio_net.c:5882)     xp_assign_dev+0x369/0x670 (net/xdp/xsk_buff_pool.c:226)     xsk_bind+0x6a5/0x1ae0     __sys_bind+0x15e/0x230     __x64_sys_bind+0x72/0xb0     do_syscall_64+0xc1/0x1d0     entry_SYSCALL_64_after_hwframe+0x77/0x7f","modified":"2026-08-27T23:05:20.820133677Z","published":"2025-05-20T16:15:33.710Z","upstream":["CVE-2025-37955"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-37955"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37955.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37955.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}