CVE-2025-38097 is a reference leak in the Linux kernel's ESP-in-TCP (espintcp) encapsulation-socket caching. An xfrm_state retains a cached userspace encapsulation socket, which in turn holds a reference to its network namespace. If the ESP-in-TCP state is not deleted before namespace teardown, the retained references can prevent namespace deletion. Once all processes in the namespace terminate, the namespace may become unreachable, preventing removal of the state needed to release the socket reference. The resulting resource leak can potentially cause denial of service through namespace-resource exhaustion.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A reference leak in the Linux kernel's espintcp encapsulation socket caching can prevent network namespace cleanup. An XFRM state retains a socket reference, which in turn retains the namespace, potentially leaving resources unreachable after processes terminate. The advisory assigns CVSS v3 severity 5.5, indicating a local, low-privilege vulnerability with high availability impact. The fix removes socket caching, with an approximately 2% performance regression reported in testing.
A reference leak in Linux kernel ESP-in-TCP encapsulation socket caching can prevent network namespaces from being deleted. Cached sockets retain namespace references through XFRM states, potentially leaving unreachable namespaces allocated after their processes terminate. The advisory assigns CVSS v3 severity 5.5, with local access, low privileges, and high availability impact. The fix removes socket caching, with an approximately 2% performance regression reported in testing.
A Linux kernel ESP-in-TCP reference-leak vulnerability caused by caching an encapsulation socket. Under certain network-namespace deletion conditions, the cached userspace socket retains a netns reference that cannot be released, resulting in an availability impact.
Linux kernel espintcp vulnerability involving a reference leak caused by encapsulation socket caching.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.