Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-38190


In the Linux kernel, the following vulnerability has been resolved: atm: Revert atm_account_tx() if copy_from_iter_full() fails. In vcc_sendmsg(), we account skb->truesize to sk->sk_wmem_alloc by atm_account_tx(). It is expected to be reverted by atm_pop_raw() later called by vcc->dev->ops->send(vcc, skb). However, vcc_sendmsg() misses the same revert when copy_from_iter_full() fails, and then we will leak a socket. Let's factorise the revert part as atm_return_tx() and call it in the failure path. Note that the corresponding sk_wmem_alloc operation can be found in alloc_tx() as of the blamed commit. $ git blame -L:alloc_tx net/atm/common.c c55fa3cccbc2c~


Published

2025-07-04T14:15:26.017

Last Modified

2025-07-08T16:18:53.607

Status

Awaiting Analysis

Source

416baaa9-dc9f-4396-8d5f-8c081fb06d67

Severity

-

Weaknesses

-


Affected Vendors & Products

-


References