cbcvebase.
CVE-2025-40292
published 2025-12-08

CVE-2025-40292: In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix received length check in big packets Since commit 4959aebba8c0…

PriorityP341high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix received length check in big packets Since commit 4959aebba8c0 ("virtio-net: use mtu size as buffer length for big packets"), when guest gso is off, the allocated size for big packets is not MAX_SKB_FRAGS * PAGE_SIZE anymore but depends on negotiated MTU. The number of allocated frags for big packets is stored in vi->big_packets_num_skbfrags. Because the host announced buffer length can be malicious (e.g. the host vhost_net driver's get_rx_bufs is modified to announce incorrect length), we need a check in virtio_net receive path. Currently, the check is not adapted to the new change which can lead to NULL page pointer dereference in the below while loop when receiving length that is larger than the allocated one. This commit fixes the received length check corresponding to the new change.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 4959aebba8c06992abafa09d1e80965e0825af54 < 82f9028e83944a9eee5229cbc6fee9be1de8a62d82f9028e83944a9eee5229cbc6fee9be1de8a62d
linuxlinux>= 4959aebba8c06992abafa09d1e80965e0825af54 < 946dec89c41726b94d31147ec528b96af0be1b5a946dec89c41726b94d31147ec528b96af0be1b5a
linuxlinux>= 4959aebba8c06992abafa09d1e80965e0825af54 < 82fe78065450d2d07f36a22e2b6b44955cf5ca5b82fe78065450d2d07f36a22e2b6b44955cf5ca5b
linuxlinux>= 4959aebba8c06992abafa09d1e80965e0825af54 < 3e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e23e9d89f2ecd3636bd4cbdfd0b2dfdaf58f9882e2
linuxlinux>= 4959aebba8c06992abafa09d1e80965e0825af54 < 0c716703965ffc5ef4311b65cb5d84a7037847170c716703965ffc5ef4311b65cb5d84a703784717
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.1.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.