CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-21788: net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases

Description

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases

If the XDP program doesn't result in XDP_PASS then we leak the
memory allocated by am65_cpsw_build_skb().

It is pointless to allocate SKB memory before running the XDP
program as we would be wasting CPU cycles for cases other than XDP_PASS.
Move the SKB allocation after evaluating the XDP program result.

This fixes the memleak. A performance boost is seen for XDP_DROP test.

XDP_DROP test:
Before: 460256 rx/s 0 err/s
After: 784130 rx/s 0 err/s

Classification

CVE ID: CVE-2025-21788

Affected Products

Vendor: Linux, Linux

Product: Linux, Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 1.68% (scored less or equal to compared to others)

EPSS Date: 2025-03-27 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-21788
https://git.kernel.org/stable/c/1bba1d042107167164a0ae3a843fdf650ab005d7
https://git.kernel.org/stable/c/dc11f049612b9d926aca2e55f8dc9d82850d0da3
https://git.kernel.org/stable/c/5db843258de1e4e6b1ef1cbd1797923c9e3de548

Timeline