CVE Vulnerabilities

CVE-2025-49488

Improper Resource Shutdown or Release

Published: Jul 01, 2025 | Modified: Dec 22, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router

components

allows Resource Leak Exposure. This vulnerability is associated with program files router/phonebook/pb.c.

This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.

Weakness

The product does not release or incorrectly releases a resource before it is made available for re-use.

Affected Software

NameVendorStart VersionEnd Version
Falcon_linuxAsrmicro*1536 (excluding)
KestrelAsrmicro*1536 (excluding)
Lapwing_linuxAsrmicro*1536 (excluding)

Potential Mitigations

  • Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, languages such as Java, Ruby, and Lisp perform automatic garbage collection that releases memory for objects that have been deallocated.

References