In the Linux kernel, the following vulnerability has been resolved:
espintcp: fix skb leaks
A few error paths are missing a kfree_skb.
[
{
"id": "CVE-2025-38057-1844e208",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076",
"target": {
"file": "net/xfrm/espintcp.c",
"function": "espintcp_queue_out"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 240.0,
"function_hash": "177006546006789156379969961655861575800"
}
},
{
"id": "CVE-2025-38057-270f341e",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f",
"target": {
"file": "net/xfrm/espintcp.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"317244675499272915439138935153638191403",
"11399526634604841781618104011468593256",
"18381763933325530528564698159630231527",
"223849348140129745141022621326663741370",
"123670545642943573106952686159140827741"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-2781f215",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157",
"target": {
"file": "net/xfrm/espintcp.c",
"function": "espintcp_queue_out"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 240.0,
"function_hash": "177006546006789156379969961655861575800"
}
},
{
"id": "CVE-2025-38057-393c3e74",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076",
"target": {
"file": "net/ipv4/esp4.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"125800312794632689940270636345613537575",
"52522577446151700897408279904044363767",
"278157151534944029501973209530438951801",
"125087642642230456057054545408617556237",
"293254119149149970074394387529363164554"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-4c098fc4",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076",
"target": {
"file": "net/xfrm/espintcp.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"317244675499272915439138935153638191403",
"11399526634604841781618104011468593256",
"18381763933325530528564698159630231527",
"223849348140129745141022621326663741370",
"123670545642943573106952686159140827741"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-4cae15a6",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076",
"target": {
"file": "net/ipv6/esp6.c",
"function": "esp_output_tcp_finish"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 341.0,
"function_hash": "103811662120127062348343333070462933278"
}
},
{
"id": "CVE-2025-38057-5d469693",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f",
"target": {
"file": "net/ipv6/esp6.c",
"function": "esp_output_tcp_finish"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 341.0,
"function_hash": "103811662120127062348343333070462933278"
}
},
{
"id": "CVE-2025-38057-67120b16",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f",
"target": {
"file": "net/ipv4/esp4.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"125800312794632689940270636345613537575",
"52522577446151700897408279904044363767",
"278157151534944029501973209530438951801",
"125087642642230456057054545408617556237",
"293254119149149970074394387529363164554"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-68115110",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157",
"target": {
"file": "net/ipv4/esp4.c",
"function": "esp_output_tcp_finish"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 341.0,
"function_hash": "103811662120127062348343333070462933278"
}
},
{
"id": "CVE-2025-38057-75a80ecc",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076",
"target": {
"file": "net/ipv6/esp6.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"44641761696476191129002800552643641322",
"205252438199644145343705475118968818939",
"278157151534944029501973209530438951801",
"125087642642230456057054545408617556237",
"293254119149149970074394387529363164554"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-859843c3",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63c1f19a3be3169e51a5812d22a6d0c879414076",
"target": {
"file": "net/ipv4/esp4.c",
"function": "esp_output_tcp_finish"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 341.0,
"function_hash": "103811662120127062348343333070462933278"
}
},
{
"id": "CVE-2025-38057-a214b6fb",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f",
"target": {
"file": "net/ipv4/esp4.c",
"function": "esp_output_tcp_finish"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 341.0,
"function_hash": "103811662120127062348343333070462933278"
}
},
{
"id": "CVE-2025-38057-accb0ed2",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f",
"target": {
"file": "net/ipv6/esp6.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"44641761696476191129002800552643641322",
"205252438199644145343705475118968818939",
"278157151534944029501973209530438951801",
"125087642642230456057054545408617556237",
"293254119149149970074394387529363164554"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-c7358486",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157",
"target": {
"file": "net/ipv6/esp6.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"44641761696476191129002800552643641322",
"205252438199644145343705475118968818939",
"278157151534944029501973209530438951801",
"125087642642230456057054545408617556237",
"293254119149149970074394387529363164554"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-ca359cc6",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157",
"target": {
"file": "net/ipv6/esp6.c",
"function": "esp_output_tcp_finish"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 341.0,
"function_hash": "103811662120127062348343333070462933278"
}
},
{
"id": "CVE-2025-38057-e0be9823",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eb058693dfc93ed7a9c365adb899fedd648b9d9f",
"target": {
"file": "net/xfrm/espintcp.c",
"function": "espintcp_queue_out"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 240.0,
"function_hash": "177006546006789156379969961655861575800"
}
},
{
"id": "CVE-2025-38057-e159fe9d",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157",
"target": {
"file": "net/ipv4/esp4.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"125800312794632689940270636345613537575",
"52522577446151700897408279904044363767",
"278157151534944029501973209530438951801",
"125087642642230456057054545408617556237",
"293254119149149970074394387529363164554"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38057-eded104c",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@28756f22de48d25256ed89234b66b9037a3f0157",
"target": {
"file": "net/xfrm/espintcp.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"317244675499272915439138935153638191403",
"11399526634604841781618104011468593256",
"18381763933325530528564698159630231527",
"223849348140129745141022621326663741370",
"123670545642943573106952686159140827741"
],
"threshold": 0.9
}
}
]