Linux Kernel NFP Driver Resource Leak Vulnerability Due to Uncleaned Multicast Addresses

Vulnerability

A resource leak vulnerability has been identified in the Linux kernel's Netronome NFP driver. When devices are moved between namespaces, multicast addresses are removed from software management but remain in the application firmware, leading to a resource leak. The vulnerability affects the Linux kernel stable tree. The issue has been addressed by modifying the driver to use the '__dev_mc_unsync' function to properly clean up multicast addresses in the firmware when a port is closed.

Impact

The vulnerability can lead to a resource leak by not properly cleaning up multicast addresses in application firmware, potentially causing issues related to resource management and availability.

Added: Dec 24, 2025, 3:00 PM
Updated: Dec 24, 2025, 3:00 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
1.5
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.