<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 18:33:13 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-22058 — udp: Fix memory accounting leak.</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-22058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;udp: Fix memory accounting leak.&lt;/p&gt;
&lt;p&gt;Matt Dowling reported a weird UDP memory usage issue.&lt;/p&gt;
&lt;p&gt;Under normal operation, the UDP memory usage reported in /proc/net/sockstat
remains close to zero.  However, it occasionally spiked to 524,288 pages
and never dropped.  Moreover, the value doubled when the application was
terminated.  Finally, it caused intermittent packet drops.&lt;/p&gt;
&lt;p&gt;We can reproduce the issue with the script below [0]:&lt;/p&gt;
&lt;p&gt;1. /proc/net/sockstat reports 0 pages&lt;/p&gt;
&lt;p&gt;# cat /proc/net/sockstat | grep UDP:
    UDP: inuse 1 mem 0&lt;/p&gt;
&lt;p&gt;2. Run the script till the report reaches 524,288&lt;/p&gt;
&lt;p&gt;# python3 test.py &amp;amp; sleep 5
    # cat /proc/net/sockstat | grep UDP:
    UDP: inuse 3 mem 524288  &amp;lt;-- (INT_MAX + 1) &amp;gt;&amp;gt; PAGE_SHIFT&lt;/p&gt;
&lt;p&gt;3. Kill the socket and confirm the number never drops&lt;/p&gt;
&lt;p&gt;# pkill python3 &amp;amp;&amp;amp; sleep 5
    # cat /proc/net/sockstat | grep UDP:
    UDP: inuse 1 mem 524288&lt;/p&gt;
&lt;p&gt;4. (necessary since v6.0) Trigger proto_memory_pcpu_drain()&lt;/p&gt;
&lt;p&gt;# python3 test.py &amp;amp; sleep 1 &amp;amp;&amp;amp; pkill python3&lt;/p&gt;
&lt;p&gt;5. The number doubles&lt;/p&gt;
&lt;p&gt;# cat /proc/net/sockstat | grep UDP:
    UDP: inuse 1 mem 1048577&lt;/p&gt;
&lt;p&gt;The application set INT_MAX to SO_RCVBUF, which triggered an integer
overflow in udp_rmem_release().&lt;/p&gt;
&lt;p&gt;When a socket is close()d, udp_destruct_common() purges its receive
queue and sums up skb-&amp;gt;truesize in the queue.  This total is calculated
and stored in a local unsigned integer variable.&lt;/p&gt;
&lt;p&gt;The total size is then passed to udp_rmem_release()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;udp: Fix memory accounting leak.&lt;/p&gt;
&lt;p&gt;Matt Dowling reported a weird UDP memory usage issue.&lt;/p&gt;
&lt;p&gt;Under normal operation, the UDP memory usage reported in /proc/net/sockstat
remains close to zero.  However, it occasionally spiked to 524,288 pages
and never dropped.  Moreover, the value doubled when the application was
terminated.  Finally, it caused intermittent packet drops.&lt;/p&gt;
&lt;p&gt;We can reproduce the issue with the script below [0]:&lt;/p&gt;
&lt;p&gt;1. /proc/net/sockstat reports 0 pages&lt;/p&gt;
&lt;p&gt;# cat /proc/net/sockstat | grep UDP:
    UDP: inuse 1 mem 0&lt;/p&gt;
&lt;p&gt;2. Run the script till the report reaches 524,288&lt;/p&gt;
&lt;p&gt;# python3 test.py &amp;amp; sleep 5
    # cat /proc/net/sockstat | grep UDP:
    UDP: inuse 3 mem 524288  &amp;lt;-- (INT_MAX + 1) &amp;gt;&amp;gt; PAGE_SHIFT&lt;/p&gt;
&lt;p&gt;3. Kill the socket and confirm the number never drops&lt;/p&gt;
&lt;p&gt;# pkill python3 &amp;amp;&amp;amp; sleep 5
    # cat /proc/net/sockstat | grep UDP:
    UDP: inuse 1 mem 524288&lt;/p&gt;
&lt;p&gt;4. (necessary since v6.0) Trigger proto_memory_pcpu_drain()&lt;/p&gt;
&lt;p&gt;# python3 test.py &amp;amp; sleep 1 &amp;amp;&amp;amp; pkill python3&lt;/p&gt;
&lt;p&gt;5. The number doubles&lt;/p&gt;
&lt;p&gt;# cat /proc/net/sockstat | grep UDP:
    UDP: inuse 1 mem 1048577&lt;/p&gt;
&lt;p&gt;The application set INT_MAX to SO_RCVBUF, which triggered an integer
overflow in udp_rmem_release().&lt;/p&gt;
&lt;p&gt;When a socket is close()d, udp_destruct_common() purges its receive
queue and sums up skb-&amp;gt;truesize in the queue.  This total is calculated
and stored in a local unsigned integer variable.&lt;/p&gt;
&lt;p&gt;The total size is then passed to udp_rmem_release()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-22058</guid>
    </item>
  </channel>
</rss>
