Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
SSVC decision
Not assessed by CISA
EPSS probability
0.18% probability of exploitation activity in the next 30 days.
EPSS percentile
Ranks above 7.7% of scored records. A rank, not a probability.
NVD base score
5.5 (CVSS v3.x), scored by the NVD independently of the CNA.
NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD analysis status
Analyzed. NVD last modified this record on 2026-06-17.
Red Hat severity
Low. Red Hat's rating for its own products, not a CVSS rating.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
04 Metadata
SCHEMA: 5.2
Published
2025-05-20 17:09Z1 YR AGO
Last updated
2026-05-11 21:19Z3 MO AGO
Reserved
2025-04-16
Assigning CNA
Linux
Record state
PUBLISHED
Severity
Not rated by the issuing CNA
CNA CVSS vector
Not published by the issuing CNA
Weaknesses
CWE-401Missing Release of Memory after Effective LifetimeVariant
LinuxLinuxf931551bafe1f10ded7f5282e2aa162c267a2e5d to < 5e280cce3a29b7fe7b828c6ccd5aa5ba87ceb6b6, f931551bafe1f10ded7f5282e2aa162c267a2e5d to < 3c2fde33e3e505dfd1a895d1f24bad650c655e14, f931551bafe1f10ded7f5282e2aa162c267a2e5d to < 5fe708c5e3c8b2152c6caaa67243e431a5d6cca3, f931551bafe1f10ded7f5282e2aa162c267a2e5d to < 545defa656568c74590317cd30068f85134a8216, f931551bafe1f10ded7f5282e2aa162c267a2e5d to < 5d53e88d8370b9ab14dd830abb410d9a2671edb6, f931551bafe1f10ded7f5282e2aa162c267a2e5d to < 47ab2caba495c1d6a899d284e541a8df656dcfe9, f931551bafe1f10ded7f5282e2aa162c267a2e5d to < 24faa6ea274a2b96d0a78a0996c3137c2b2a65f0, f931551bafe1f10ded7f5282e2aa162c267a2e5d to < bdb43af4fdb39f844ede401bdb1258f67a580a27, 2.6.35—