CVE-2025-38079

Published Jun 18, 2025

Last updated 4 months ago

Overview

Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type algif_hash with MSG_MORE flag set and crypto_ahash_import fails, sk2 is freed. However, it is also freed in af_alg_release, leading to slab-use-after-free error.
Source
416baaa9-dc9f-4396-8d5f-8c081fb06d67
NVD status
Analyzed
Products
linux_kernel, debian_linux

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-415

Social media

Hype score
Not currently trending
  1. ๐Ÿ” CRITICAL SECURITY UPDATE: #SUSE has released Live Patch 10 for SLE 15 SP6 to address four severe Linux kernel vulnerabilities (CVE-2025-38079, CVE-2025-38083, CVE-2025-38494, CVE-2025-38495). Read more:๐Ÿ‘‰ https://t.co/5YM9f2Q65j #Security https://t.co/uOIWxyLxDi

    @Cezar_H_Linux

    22 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ๐Ÿ” CRITICAL SECURITY UPDATE for @SUSE & @openSUSE users. Live Patch 59 for SLE 15 SP3 / Leap 15.3 patches 3 kernel vulnerabilities: CVE-2025-38494 (CVSS 8.5) CVE-2025-38495 (CVSS 8.5) CVE-2025-38079 (CVSS 7.3) Read more:๐Ÿ‘‰ https://t.co/XSUmOav4

    @Cezar_H_Linux

    22 Aug 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. URGENT: Patch your #SUSE Linux systems now! New kernel update fixes 5 critical vulnerabilities (CVSS up to 8.5): โœ… CVE-2025-38494. โœ… CVE-2025-38495. โœ… CVE-2025-38079. Affects: SLE 15 SP3, Leap 15.3. Read more:๐Ÿ‘‰ https://t.co/fDkvsYuDOK #Security https://t.co/UUYWk2VlHp

    @Cezar_H_Linux

    22 Aug 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. URGENT: Patch #SUSE SLE 15 SP6 NOW. Live Patch 11 fixes 4 critical kernel vulnerabilities (CVE-2025-38494, CVE-2025-38495, CVE-2025-38079, CVE-2025-38083) with CVSS scores up to 8.5. Don't risk a breach. Read more:๐Ÿ‘‰ https://t.co/Inku2xAAwA #Security https://t.co/hkVOvbNo6c

    @Cezar_H_Linux

    22 Aug 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. URGENT: #SUSE releases critical kernel security patch for SLE 15 SP6 / openSUSE Leap 15.6. Patches 4 vulnerabilities: โœ… CVE-2025-38494 (CVSS 8.5) โœ… CVE-2025-38495 (CVSS 8.5) โœ… CVE-2025-38079 โœ… CVE-2025-38083 Read more: ๐Ÿ‘‰ https://t.co/anKbMUMkxS https://t.co/F367XNvS0u

    @Cezar_H_Linux

    21 Aug 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ๐Ÿšจ URGENT #Security Update for #Ubuntu 22.04 LTS users. Multiple critical vulnerabilities (CVE-2025-38079, etc.) patched in the Linux FIPS kernel. Affects Crypto API, Network, & NVMe drivers. Read more:๐Ÿ‘‰ https://t.co/ryYbDzUwSM https://t.co/kdIYZgJmzZ

    @Cezar_H_Linux

    20 Aug 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ๐Ÿšจ Critical kernel update! #SUSEโ€™s Live Patch 38 fixes: โœ… CVE-2025-38494 (8.5) - HID bypass. โœ… CVE-2025-38079 - Crypto double-free. โœ… 3 other CVEs. Read more:๐Ÿ‘‰ https://t.co/Rv9Q9w8D0J #Security https://t.co/y6ari0EIUs

    @Cezar_H_Linux

    18 Aug 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Critical #SUSE kernel update! Patch now for: โœ… CVE-2025-38494/95 (CVSS 8.5 - USB privilege escalation). โœ… CVE-2025-38079 (RCE via crypto API). โœ… 3 other high-risk flaws. Read more: ๐Ÿ‘‰ https://t.co/a6R0CxGfem #Security https://t.co/jTEVRJrTa0

    @Cezar_H_Linux

    18 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  9. ๐Ÿšจ #SUSE Kernel Patch 68: Fixes 4 HIGH-risk CVEs (CVE-2025-38494/5, CVE-2025-38079/83). โœ… CVSS 8.5: HID heap overflows โ†’ root access โœ… SLE 12 SP5 affected โฐ Patch IMMEDIATELY. Read more:๐Ÿ‘‰ https://t.co/8UyqXdbxk4 #Security https://t.co/is9yDCKTtw

    @Cezar_H_Linux

    18 Aug 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. โ€ผ๏ธ CRITICAL #Linux Kernel Patches: #SUSE SU-2025:02827-1 for SLE 12 SP5 (Live Patch 67) fixes 4 vulns (CVE-2025-38494/5, CVE-2025-38079/83). CVSS 8.5! Local priv escalation/code exec risk. โš ๏ธ Read more: ๐Ÿ‘‰ https://t.co/TqhCNYU3Rr #Security https://t.co/c1hSjcTcsW

    @Cezar_H_Linux

    18 Aug 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. ๐Ÿšจ Breaking: #SUSE kernel update (SU-2025:02820-1) patches: CVE-2025-38494 (HID hijacking) CVE-2025-38079 (Crypto crash) Patch IMMEDIATELY if using #Linux Real-Time. Details. Read more: ๐Ÿ‘‰ https://t.co/h8HRH5pyGM #Security https://t.co/aSsax12lub

    @Cezar_H_Linux

    18 Aug 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2025-38079 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type algif_โ€ฆ https://t.co/Tpem3L8548

    @CVEnew

    18 Jun 2025

    163 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations