cbcvebase.
CVE-2025-37998
published 2025-05-29

CVE-2025-37998: In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch replaces the…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch replaces the manual Netlink attribute iteration in output_userspace() with nla_for_each_nested(), which ensures that only well-formed attributes are processed.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.139-1 (bookworm)linux 6.1.139-1 (bookworm)
debianlinux-6.1< linux 6.1.139-1 (bookworm)linux 6.1.139-1 (bookworm)
linuxlinux
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < 6712dc21506738f5f22b4f68b7c0d9e0df819dbd6712dc21506738f5f22b4f68b7c0d9e0df819dbd
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < 06b4f110c79716c181a8c5da007c25980784023206b4f110c79716c181a8c5da007c259807840232
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < 47f7f00cf2fa3137d5c0416ef1a71bdf7790139547f7f00cf2fa3137d5c0416ef1a71bdf77901395
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < bca8df998cce1fead8cbc69144862eadc2e34c87bca8df998cce1fead8cbc69144862eadc2e34c87
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < 0236742bd959332181c1fcc41a05b7b7091805010236742bd959332181c1fcc41a05b7b709180501
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < ec334aaab74705cc515205e1da3cb369fdfd93cdec334aaab74705cc515205e1da3cb369fdfd93cd
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < 4fa672cbce9c86c3efb8621df1ae580d478134304fa672cbce9c86c3efb8621df1ae580d47813430
linuxlinux>= ccb1352e76cff0524e7ccb2074826a092dd13016 < 6beb6835c1fbb3f676aebb51a5fee6b77fed93086beb6835c1fbb3f676aebb51a5fee6b77fed9308
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.139-16.1.139-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 3.3 < 5.4.2945.4.294
linuxlinux_kernel>= 5.11 < 5.15.1835.15.183
linuxlinux_kernel>= 5.16 < 6.1.1396.1.139
linuxlinux_kernel>= 5.5 < 5.10.2385.10.238
linuxlinux_kernel>= 6.13 < 6.14.76.14.7
linuxlinux_kernel>= 6.2 < 6.6.916.6.91

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH