DEBIAN-CVE-2025-38190
In the Linux kernel, the following vulnerability has been resolved: atm: Revert atm_account_tx() if copy_from_iter_full() fails. In vcc_sendmsg(), we account skb->truesize to sk->sk_wmem_alloc by atm_account_tx(). It is expected to be reverted by atm_pop_raw() later called by vcc->dev->ops->send(vcc, skb). However, vcc_sendmsg() misses the same revert when copy_from_iter_full() fails, and then we will leak a socket. Let's factorise the revert part as atm_return_tx() and call it in the failure path. Note that the corresponding sk_wmem_alloc operation can be found in alloc_tx() as of the blamed commit. $ git blame -L:alloc_tx net/atm/common.c c55fa3cccbc2c~
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | linux | 0, 0 |
| Debian:12 | linux | 6.1.69-1, 6.1.69-1~bpo11+1, * |
| Debian:11 | linux-6.1 | 6.1.106-3, 6.1.119-1, 6.1.128-1 |
| Debian:14 | linux | 0, 0 |
| Debian:11 | linux | 5.10.216-1, 5.10.103-1, 5.10.103-1~bpo10+1 |
Timeline
- Jul 4, 2025 CVE Published
- Apr 28, 2026 CVE Updated