Executive brief
A vulnerability in the Linux kernel's Point-to-Point Protocol (PPP) component can lead to a memory leak. PPP is a common method for establishing network connections between two nodes. If exploited, this flaw could allow a local user to gradually consume system memory, potentially leading to system instability or a crash (denial of service).
Technical details
A memory leak exists in the 'pad_compress_skb' function within 'drivers/net/ppp/ppp_generic.c'. When 'alloc_skb()' fails during compression, the function returns NULL without releasing the original socket buffer (skb). Because the caller overwrites its only reference to the skb with the NULL return value, the memory cannot be freed, leading to a leak. An attacker with local access could potentially trigger this condition repeatedly to exhaust system memory. The fix aligns the function's semantics with 'realloc()', ensuring the original buffer is preserved or properly handled upon failure.
Affected products
- Linux Linux Kernel 2.6.15 to 5.4.299, 5.5 to 5.10.243, 5.11 to 5.15.192, 5.16 to 6.1.151, 6.2 to 6.6.105, 6.7 to 6.12.46, 6.13 to 6.16.6
Timeline
- 2025-09-03: patched: Initial patch submitted by Qingfang Deng
- 2025-09-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0b21e9cd4559102da798bdcba453b64ecd7be7ee
- https://git.kernel.org/stable/c/1d8b354eafb8876d8bdb1bef69c7d2438aacfbe8
- https://git.kernel.org/stable/c/33a5bac5f14772730d2caf632ae97b6c2ee95044
- https://git.kernel.org/stable/c/4844123fe0b853a4982c02666cb3fd863d701d50
- https://git.kernel.org/stable/c/631fc8ab5beb9e0ec8651fb9875b9a968e7b4ae4
- https://git.kernel.org/stable/c/85c1c86a67e09143aa464e9bf09c397816772348
- https://git.kernel.org/stable/c/87a35a36742df328d0badf4fbc2e56061c15846c