Linux Kernel Net/Mlx5e Memory Leak Vulnerability Due to Improper Label Mapping Release

Vulnerability

A memory leak vulnerability has been identified in the Linux kernel's net/mlx5e component. The issue arises because the label mapping is not properly released when an existing connection tracking (ct) entry is replaced. This oversight leads to unreferenced objects, causing a memory leak. The vulnerability has been addressed in the official Linux Git repository.

Impact

The vulnerability causes a memory leak by failing to release label mappings, leading to unreferenced objects and increased memory usage.

Remediation

Users can apply the patch available in the Linux kernel stable tree to address this vulnerability.

Added: Oct 22, 2025, 2:37 PM
Updated: Oct 22, 2025, 2:37 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
7.7
relevance
0.8
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.