cbcvebase.
CVE-2025-38375
published 2025-07-25

CVE-2025-38375: In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exceed allocated size In…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exceed allocated size In xdp_linearize_page, when reading the following buffers from the ring, we forget to check the received length with the true allocate size. This can lead to an out-of-bound read. This commit adds that missing check.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < 773e95c268b5d859f51f7547559734fd2a57660c773e95c268b5d859f51f7547559734fd2a57660c
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < ddc8649d363141fb3371dd81a73e1cb4ef8ed1e1ddc8649d363141fb3371dd81a73e1cb4ef8ed1e1
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < 982beb7582c193544eb9c6083937ec5ac1c9d651982beb7582c193544eb9c6083937ec5ac1c9d651
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < 6aca3dad2145e864dfe4d1060f45eb1bac75dd586aca3dad2145e864dfe4d1060f45eb1bac75dd58
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < 80b971be4c37a4d23a7f1abc5ff33dc7733d649b80b971be4c37a4d23a7f1abc5ff33dc7733d649b
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < bc68bc3563344ccdc57d1961457cdeecab8f81efbc68bc3563344ccdc57d1961457cdeecab8f81ef
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < 11f2d0e8be2b5e784ac45fa3da226492c3e506d811f2d0e8be2b5e784ac45fa3da226492c3e506d8
linuxlinux>= 4941d472bf95b4345d6e38906fcf354e74afa311 < 315dbdd7cdf6aa533829774caaf4d25f1fd20e73315dbdd7cdf6aa533829774caaf4d25f1fd20e73
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 5.15.0-156.1665.15.0-156.166
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 4.14 < 5.4.2975.4.297
linuxlinux_kernel>= 5.11 < 5.15.1895.15.189
linuxlinux_kernel>= 5.16 < 6.1.1446.1.144
linuxlinux_kernel>= 5.5 < 5.10.2415.10.241
linuxlinux_kernel>= 6.13 < 6.15.66.15.6
linuxlinux_kernel>= 6.2 < 6.6.976.6.97

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH