CVE-2025-38375

Advisory lineage Upstream: 0 Downstream: 61
Analyzed
Published: 25 Jul 2025, 12:53
Last modified:11 May 2026, 21:26

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.17% LOW
0% probability +0.15%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Jul 2025, 12:53
Published
Vulnerability first disclosed
11 May 2026, 21:26
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exceed allocated size In xdp_linearize_page, when reading the following buffers from the ring, we forget to check the received length with the true allocate size. This can lead to an out-of-bound read. This commit adds that missing check.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.17% Percentile: 7%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • debiandebian_linux

    11.0

  • linuxlinux

    ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < 773e95c268b5d859f51f7547559734fd2a57660c | ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < ddc8649d363141fb3371dd81a73e1cb4ef8ed1e1 | ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < 982beb7582c193544eb9c6083937ec5ac1c9d651 | ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < 6aca3dad2145e864dfe4d1060f45eb1bac75dd58 | ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < 80b971be4c37a4d23a7f1abc5ff33dc7733d649b | ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < bc68bc3563344ccdc57d1961457cdeecab8f81ef | ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < 11f2d0e8be2b5e784ac45fa3da226492c3e506d8 | ≥ 4941d472bf95b4345d6e38906fcf354e74afa311, < 315dbdd7cdf6aa533829774caaf4d25f1fd20e73 | 4.14

  • linuxlinux kernel

    ≥ 4.14, < 5.4.297 | ≥ 5.5, < 5.10.241 | ≥ 5.11, < 5.15.189 | ≥ 5.16, < 6.1.144 | ≥ 6.2, < 6.6.97 | ≥ 6.7, < 6.12.37 | ≥ 6.13, < 6.15.6 | 6.16:rc1 | 6.16:rc2 | 6.16:rc3 | 6.16:rc4

References (10)