In the Linux kernel, the following vulnerability has been resolved:
espintcp: fix skb leaks
A few error paths are missing a kfree_skb.
[ { "signature_type": "Function", "id": "CVE-2025-38057-1844e208", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076", "signature_version": "v1", "target": { "function": "espintcp_queue_out", "file": "net/xfrm/espintcp.c" }, "digest": { "function_hash": "177006546006789156379969961655861575800", "length": 240.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-270f341e", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f", "signature_version": "v1", "target": { "file": "net/xfrm/espintcp.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "317244675499272915439138935153638191403", "11399526634604841781618104011468593256", "18381763933325530528564698159630231527", "223849348140129745141022621326663741370", "123670545642943573106952686159140827741" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-2781f215", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157", "signature_version": "v1", "target": { "function": "espintcp_queue_out", "file": "net/xfrm/espintcp.c" }, "digest": { "function_hash": "177006546006789156379969961655861575800", "length": 240.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-393c3e74", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076", "signature_version": "v1", "target": { "file": "net/ipv4/esp4.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "125800312794632689940270636345613537575", "52522577446151700897408279904044363767", "278157151534944029501973209530438951801", "125087642642230456057054545408617556237", "293254119149149970074394387529363164554" ] }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-4c098fc4", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076", "signature_version": "v1", "target": { "file": "net/xfrm/espintcp.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "317244675499272915439138935153638191403", "11399526634604841781618104011468593256", "18381763933325530528564698159630231527", "223849348140129745141022621326663741370", "123670545642943573106952686159140827741" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-4cae15a6", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076", "signature_version": "v1", "target": { "function": "esp_output_tcp_finish", "file": "net/ipv6/esp6.c" }, "digest": { "function_hash": "103811662120127062348343333070462933278", "length": 341.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-5d469693", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f", "signature_version": "v1", "target": { "function": "esp_output_tcp_finish", "file": "net/ipv6/esp6.c" }, "digest": { "function_hash": "103811662120127062348343333070462933278", "length": 341.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-67120b16", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f", "signature_version": "v1", "target": { "file": "net/ipv4/esp4.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "125800312794632689940270636345613537575", "52522577446151700897408279904044363767", "278157151534944029501973209530438951801", "125087642642230456057054545408617556237", "293254119149149970074394387529363164554" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-68115110", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157", "signature_version": "v1", "target": { "function": "esp_output_tcp_finish", "file": "net/ipv4/esp4.c" }, "digest": { "function_hash": "103811662120127062348343333070462933278", "length": 341.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-75a80ecc", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076", "signature_version": "v1", "target": { "file": "net/ipv6/esp6.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "44641761696476191129002800552643641322", "205252438199644145343705475118968818939", "278157151534944029501973209530438951801", "125087642642230456057054545408617556237", "293254119149149970074394387529363164554" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-859843c3", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076", "signature_version": "v1", "target": { "function": "esp_output_tcp_finish", "file": "net/ipv4/esp4.c" }, "digest": { "function_hash": "103811662120127062348343333070462933278", "length": 341.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-a214b6fb", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f", "signature_version": "v1", "target": { "function": "esp_output_tcp_finish", "file": "net/ipv4/esp4.c" }, "digest": { "function_hash": "103811662120127062348343333070462933278", "length": 341.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-accb0ed2", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f", "signature_version": "v1", "target": { "file": "net/ipv6/esp6.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "44641761696476191129002800552643641322", "205252438199644145343705475118968818939", "278157151534944029501973209530438951801", "125087642642230456057054545408617556237", "293254119149149970074394387529363164554" ] }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-c7358486", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157", "signature_version": "v1", "target": { "file": "net/ipv6/esp6.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "44641761696476191129002800552643641322", "205252438199644145343705475118968818939", "278157151534944029501973209530438951801", "125087642642230456057054545408617556237", "293254119149149970074394387529363164554" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-ca359cc6", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157", "signature_version": "v1", "target": { "function": "esp_output_tcp_finish", "file": "net/ipv6/esp6.c" }, "digest": { "function_hash": "103811662120127062348343333070462933278", "length": 341.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2025-38057-e0be9823", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f", "signature_version": "v1", "target": { "function": "espintcp_queue_out", "file": "net/xfrm/espintcp.c" }, "digest": { "function_hash": "177006546006789156379969961655861575800", "length": 240.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-e159fe9d", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157", "signature_version": "v1", "target": { "file": "net/ipv4/esp4.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "125800312794632689940270636345613537575", "52522577446151700897408279904044363767", "278157151534944029501973209530438951801", "125087642642230456057054545408617556237", "293254119149149970074394387529363164554" ] }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2025-38057-eded104c", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157", "signature_version": "v1", "target": { "file": "net/xfrm/espintcp.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "317244675499272915439138935153638191403", "11399526634604841781618104011468593256", "18381763933325530528564698159630231527", "223849348140129745141022621326663741370", "123670545642943573106952686159140827741" ] }, "deprecated": false } ]