CVE-2025-38015: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc Memory allocated for idxd is not freed if an error occurs during idxd_alloc(). To fix it, free the allocated memory in the reverse order of allocation before exiting the function in case of an error.
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 6.0.9, before 6.1.140 (fixed in 6.1.140); from 6.2, before 6.6.92 (fixed in 6.6.92); from 6.7, before 6.12.30 (fixed in 6.12.30); from 6.13, before 6.14.8 (fixed in 6.14.8); version 6.15 only
Published 2025-06-18. Last modified 2026-06-17.