CVE-2025-39830: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path In the error path of hws_pool_buddy_init(), the buddy allocator cleanup doesn't free the allocator structure itself, causing a memory leak. Add the missing kfree() to properly release all allocated memory.
Affected products
- Linux Linux Kernel: from 6.12, before 6.16.5 (fixed in 6.16.5); version 6.17 only
Published 2025-09-16. Last modified 2026-06-17.