CVE-2025-38258

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38258
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38258.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38258
Downstream
Related
Published
2025-07-09T10:42:35Z
Modified
2025-11-28T02:33:50.193894Z
Summary
mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/damon/sysfs-schemes: free old damonsysfsschemefilter->memcgpath on write

memcgpathstore() assigns a newly allocated memory buffer to filter->memcgpath, without deallocating the previously allocated and assigned memory buffer. As a result, users can leak kernel memory by continuously writing a data to memcgpath DAMOS sysfs file. Fix the leak by deallocating the previously set memory buffer.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38258.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7ee161f18b5da5170b5d6a51aace49d312099128
Fixed
490a43d07f1663d827e802720d30cbc0494e4f81
Fixed
c5d5b0047b0c0f304608f3824139f7bd34c48413
Fixed
4a158ac0538dd5695eeaa00aa0720d711f3e4ef1
Fixed
4f489fe6afb395dbc79840efa3c05440b760d883

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.96
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.36
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.5