CVE-2025-38079

Source
https://cve.org/CVERecord?id=CVE-2025-38079
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38079.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38079
Downstream
Related
Published
2025-06-18T09:33:53.251Z
Modified
2026-03-20T12:42:38.772691Z
Summary
crypto: algif_hash - fix double free in hash_accept
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: algifhash - fix double free in hashaccept

If accept(2) is called on socket type algifhash with MSGMORE flag set and cryptoahashimport fails, sk2 is freed. However, it is also freed in afalgrelease, leading to slab-use-after-free error.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38079.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fe869cdb89c95d060c77eea20204d6c91f233b53
Fixed
5bff312b59b3f2a54ff504e4f4e47272b64f3633
Fixed
bf7bba75b91539e93615f560893a599c1e1c98bf
Fixed
c3059d58f79fdfb2201249c2741514e34562b547
Fixed
f0f3d09f53534ea385d55ced408f2b67059b16e4
Fixed
134daaba93193df9e988524b5cd2f52d15eb1993
Fixed
2f45a8d64fb4ed4830a4b3273834ecd6ca504896
Fixed
0346f4b742345d1c733c977f3a7aef5a6419a967
Fixed
b2df03ed4052e97126267e8c13ad4204ea6ba9b6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38079.json"