[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-38463":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":20,"duplicate_of":9,"upstream":21,"downstream":22,"duplicates":109,"related":110,"reserved_at":9,"published_at":128,"modified_at":129,"state":130,"summary":131,"references_raw":140,"kevs":159,"epss":160,"epss_history":163,"metrics":425,"affected":431},"CVE-2025-38463","In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Correct signedness in skb remaining space calculation\n\nSyzkaller reported a bug [1] where sk->sk_forward_alloc can overflow.\n\nWhen we send data, if an skb exists at the tail of the write queue, the\nkernel will attempt to append the new data to that skb. However, the code\nthat checks for available space in the skb is flawed:\n'''\ncopy = size_goal - skb->len\n'''\n\nThe types of the variables involved are:\n'''\ncopy: ssize_t (s64 on 64-bit systems)\nsize_goal: int\nskb->len: unsigned int\n'''\n\nDue to C's type promotion rules, the signed size_goal is converted to an\nunsigned int to match skb->len before the subtraction. The result is an\nunsigned int.\n\nWhen this unsigned int result is then assigned to the s64 copy variable,\nit is zero-extended, preserving its non-negative value. Consequently, copy\nis always >= 0.\n\nAssume we are sending 2GB of data and size_goal has been adjusted to a\nvalue smaller than skb->len. The subtraction will result in copy holding a\nvery large positive integer. In the subsequent logic, this large value is\nused to update sk->sk_forward_alloc, which can easily cause it to overflow.\n\nThe syzkaller reproducer uses TCP_REPAIR to reliably create this\ncondition. However, this can also occur in real-world scenarios. The\ntcp_bound_to_half_wnd() function can also reduce size_goal to a small\nvalue. This would cause the subsequent tcp_wmem_schedule() to set\nsk->sk_forward_alloc to a value close to INT_MAX. Further memory\nallocation requests would then cause sk_forward_alloc to wrap around and\nbecome negative.\n\n[1]: https://syzkaller.appspot.com/bug?extid=de6565462ab540f50e47",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-191","Integer Underflow (Wrap or Wraparound)","The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.","weakness","Draft","Base",[],[],[],[],[23,25,27,29,31,33,35,37,39,41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71,73,75,77,79,81,83,85,87,89,91,93,95,97,99,101,103,105,107],{"_key":24},"SUSE-SU-2025:02853-1",{"_key":26},"SUSE-SU-2025:02923-1",{"_key":28},"SUSE-SU-2025:02969-1",{"_key":30},"SUSE-SU-2025:03023-1",{"_key":32},"DSA-5975-1",{"_key":34},"RHSA-2025:15782",{"_key":36},"SUSE-SU-2025:02997-1",{"_key":38},"SUSE-SU-2025:03011-1",{"_key":40},"SUSE-SU-2025:20577-1",{"_key":42},"SUSE-SU-2025:20586-1",{"_key":44},"SUSE-SU-2025:20601-1",{"_key":46},"SUSE-SU-2025:20602-1",{"_key":48},"SUSE-SU-2025:21074-1",{"_key":50},"SUSE-SU-2025:21139-1",{"_key":52},"SUSE-SU-2025:21179-1",{"_key":54},"SUSE-SU-2025:02996-1",{"_key":56},"OPENSUSE-SU-2025:20081-1",{"_key":58},"MGASA-2025-0218",{"_key":60},"MGASA-2025-0219",{"_key":62},"DEBIAN-CVE-2025-38463",{"_key":64},"USN-7934-1",{"_key":66},"USN-8028-1",{"_key":68},"USN-8028-2",{"_key":70},"USN-8028-3",{"_key":72},"USN-8028-4",{"_key":74},"USN-8028-5",{"_key":76},"USN-8028-6",{"_key":78},"USN-8028-7",{"_key":80},"USN-8028-8",{"_key":82},"USN-8031-1",{"_key":84},"USN-8031-2",{"_key":86},"USN-8031-3",{"_key":88},"USN-8052-1",{"_key":90},"USN-8052-2",{"_key":92},"USN-8074-1",{"_key":94},"USN-8074-2",{"_key":96},"USN-8126-1",{"_key":98},"USN-7879-1",{"_key":100},"USN-7879-2",{"_key":102},"USN-7879-3",{"_key":104},"USN-7879-4",{"_key":106},"USN-7880-1",{"_key":108},"UBUNTU-CVE-2025-38463",[],[111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127],{"_key":24},{"_key":26},{"_key":28},{"_key":30},{"_key":36},{"_key":38},{"_key":40},{"_key":42},{"_key":44},{"_key":46},{"_key":48},{"_key":50},{"_key":52},{"_key":54},{"_key":56},{"_key":58},{"_key":60},"2025-07-25T15:27:45.975Z","2026-05-11T21:28:29.864Z","Analyzed",{"cisa_kev":132,"cisa_ransomware":132,"cisa_vendor":9,"epss_severity":133,"epss_score":134,"severity":135,"severity_score":136,"severity_version":137,"severity_source":138,"severity_vector":139,"severity_status":130},false,"low",0.00077,"medium",5.5,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",[141,147,151,155],{"url":142,"sources":143,"tags":145},"https://git.kernel.org/stable/c/81373cd1d72d87c7d844d4454a526b8f53e72d00",[144,138],"cve.org",[146],"Patch",{"url":148,"sources":149,"tags":150},"https://git.kernel.org/stable/c/62e6160cfb5514787bda833d466509edc38fde23",[144,138],[146],{"url":152,"sources":153,"tags":154},"https://git.kernel.org/stable/c/9f164fa6bb09fbcc60fa5c3ff551ce9eec1befd7",[144,138],[146],{"url":156,"sources":157,"tags":158},"https://git.kernel.org/stable/c/d3a5f2871adc0c61c61869f37f3e697d97f03d8c",[144,138],[146],[],{"date":161,"score":134,"percentile":162},"2026-06-04",0.23162,[164,168,171,174,177,180,183,186,188,191,194,197,200,203,206,209,212,216,219,222,225,229,232,235,238,240,243,245,248,251,254,257,260,263,265,268,271,274,277,280,283,286,289,291,294,297,300,303,307,311,314,317,320,323,325,328,330,333,336,339,343,346,349,352,355,358,361,364,367,370,373,376,379,382,385,387,389,392,395,398,400,403,405,407,409,411,414,417,420,422],{"date":165,"score":166,"percentile":167},"2025-11-04",0.00026,0.05989,{"date":169,"score":166,"percentile":170},"2025-11-05",0.06009,{"date":172,"score":166,"percentile":173},"2025-11-06",0.06125,{"date":175,"score":166,"percentile":176},"2025-11-07",0.06134,{"date":178,"score":166,"percentile":179},"2025-11-08",0.0614,{"date":181,"score":166,"percentile":182},"2025-11-09",0.06131,{"date":184,"score":166,"percentile":185},"2025-11-10",0.06108,{"date":187,"score":166,"percentile":176},"2025-11-11",{"date":189,"score":166,"percentile":190},"2025-11-12",0.06179,{"date":192,"score":166,"percentile":193},"2025-11-13",0.06214,{"date":195,"score":166,"percentile":196},"2025-11-14",0.06242,{"date":198,"score":166,"percentile":199},"2025-11-15",0.06273,{"date":201,"score":166,"percentile":202},"2025-11-16",0.06291,{"date":204,"score":166,"percentile":205},"2025-11-17",0.06281,{"date":207,"score":166,"percentile":208},"2025-11-18",0.03766,{"date":210,"score":166,"percentile":211},"2025-11-19",0.03813,{"date":213,"score":214,"percentile":215},"2025-11-20",0.00017,0.02072,{"date":217,"score":214,"percentile":218},"2025-11-21",0.03232,{"date":220,"score":214,"percentile":221},"2025-11-22",0.03234,{"date":223,"score":214,"percentile":224},"2025-11-23",0.03228,{"date":226,"score":227,"percentile":228},"2025-11-24",0.00022,0.04797,{"date":230,"score":227,"percentile":231},"2025-11-25",0.04806,{"date":233,"score":227,"percentile":234},"2025-11-26",0.04844,{"date":236,"score":227,"percentile":237},"2025-11-27",0.04856,{"date":239,"score":227,"percentile":234},"2025-11-28",{"date":241,"score":227,"percentile":242},"2025-11-29",0.049,{"date":244,"score":227,"percentile":242},"2025-11-30",{"date":246,"score":227,"percentile":247},"2025-12-01",0.04996,{"date":249,"score":227,"percentile":250},"2025-12-02",0.05012,{"date":252,"score":227,"percentile":253},"2025-12-03",0.05038,{"date":255,"score":227,"percentile":256},"2025-12-04",0.04983,{"date":258,"score":227,"percentile":259},"2025-12-05",0.05045,{"date":261,"score":227,"percentile":262},"2025-12-06",0.0506,{"date":264,"score":227,"percentile":262},"2025-12-07",{"date":266,"score":227,"percentile":267},"2025-12-08",0.05066,{"date":269,"score":227,"percentile":270},"2025-12-09",0.05109,{"date":272,"score":227,"percentile":273},"2025-12-10",0.0517,{"date":275,"score":227,"percentile":276},"2025-12-11",0.05161,{"date":278,"score":227,"percentile":279},"2025-12-12",0.05185,{"date":281,"score":227,"percentile":282},"2025-12-13",0.05229,{"date":284,"score":227,"percentile":285},"2025-12-14",0.05217,{"date":287,"score":227,"percentile":288},"2025-12-15",0.05189,{"date":290,"score":227,"percentile":288},"2025-12-16",{"date":292,"score":227,"percentile":293},"2025-12-17",0.05252,{"date":295,"score":227,"percentile":296},"2025-12-18",0.05288,{"date":298,"score":227,"percentile":299},"2025-12-19",0.05267,{"date":301,"score":227,"percentile":302},"2025-12-20",0.05269,{"date":304,"score":305,"percentile":306},"2025-12-21",0.00011,0.00945,{"date":308,"score":309,"percentile":310},"2025-12-22",0.0001,0.00864,{"date":312,"score":309,"percentile":313},"2025-12-23",0.00861,{"date":315,"score":309,"percentile":316},"2025-12-24",0.00862,{"date":318,"score":309,"percentile":319},"2025-12-25",0.00866,{"date":321,"score":309,"percentile":322},"2025-12-26",0.00869,{"date":324,"score":309,"percentile":322},"2025-12-27",{"date":326,"score":309,"percentile":327},"2025-12-28",0.00867,{"date":329,"score":309,"percentile":310},"2025-12-29",{"date":331,"score":309,"percentile":332},"2025-12-30",0.00863,{"date":334,"score":309,"percentile":335},"2025-12-31",0.0086,{"date":337,"score":309,"percentile":338},"2026-01-01",0.00878,{"date":340,"score":341,"percentile":342},"2026-01-02",0.00015,0.02358,{"date":344,"score":341,"percentile":345},"2026-01-03",0.02359,{"date":347,"score":341,"percentile":348},"2026-01-04",0.02292,{"date":350,"score":341,"percentile":351},"2026-01-05",0.02296,{"date":353,"score":341,"percentile":354},"2026-01-06",0.02285,{"date":356,"score":341,"percentile":357},"2026-01-07",0.023,{"date":359,"score":341,"percentile":360},"2026-01-08",0.02323,{"date":362,"score":341,"percentile":363},"2026-01-09",0.02338,{"date":365,"score":341,"percentile":366},"2026-01-10",0.02344,{"date":368,"score":341,"percentile":369},"2026-01-11",0.02328,{"date":371,"score":341,"percentile":372},"2026-01-12",0.02306,{"date":374,"score":341,"percentile":375},"2026-01-13",0.02294,{"date":377,"score":341,"percentile":378},"2026-01-14",0.02298,{"date":380,"score":341,"percentile":381},"2026-01-15",0.02291,{"date":383,"score":341,"percentile":384},"2026-01-16",0.02289,{"date":386,"score":341,"percentile":348},"2026-01-17",{"date":388,"score":341,"percentile":357},"2026-01-18",{"date":390,"score":341,"percentile":391},"2026-01-19",0.02288,{"date":393,"score":341,"percentile":394},"2026-01-20",0.02275,{"date":396,"score":341,"percentile":397},"2026-01-21",0.0227,{"date":399,"score":341,"percentile":397},"2026-01-22",{"date":401,"score":341,"percentile":402},"2026-01-23",0.0228,{"date":404,"score":341,"percentile":357},"2026-01-24",{"date":406,"score":341,"percentile":348},"2026-01-25",{"date":408,"score":341,"percentile":384},"2026-01-26",{"date":410,"score":341,"percentile":348},"2026-01-27",{"date":412,"score":341,"percentile":413},"2026-01-28",0.02297,{"date":415,"score":341,"percentile":416},"2026-01-29",0.02317,{"date":418,"score":341,"percentile":419},"2026-01-30",0.02325,{"date":421,"score":341,"percentile":366},"2026-01-31",{"date":423,"score":341,"percentile":424},"2026-02-01",0.02397,[426],{"source":138,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":427,"cvss_v4_0":9},{"baseScore":136,"baseSeverity":428,"vectorString":139,"impactScore":429,"exploitabilityScore":430},"MEDIUM",6,4.6,[432,455],{"ecosystem":9,"name":433,"vendor":434,"product":434,"cpe_part":435,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":436},"Linux","linux","a",[437,444,447,450,453],{"version":438,"is_range":439,"range_type":144,"version_start":440,"version_start_type":441,"version_end":442,"version_end_type":443,"fixed_in":9},">= 270a1c3de47e49dd2fc18f48e46b101e48050e78, \u003C 81373cd1d72d87c7d844d4454a526b8f53e72d00",true,"270a1c3de47e49dd2fc18f48e46b101e48050e78","including","81373cd1d72d87c7d844d4454a526b8f53e72d00","excluding",{"version":445,"is_range":439,"range_type":144,"version_start":440,"version_start_type":441,"version_end":446,"version_end_type":443,"fixed_in":9},">= 270a1c3de47e49dd2fc18f48e46b101e48050e78, \u003C 62e6160cfb5514787bda833d466509edc38fde23","62e6160cfb5514787bda833d466509edc38fde23",{"version":448,"is_range":439,"range_type":144,"version_start":440,"version_start_type":441,"version_end":449,"version_end_type":443,"fixed_in":9},">= 270a1c3de47e49dd2fc18f48e46b101e48050e78, \u003C 9f164fa6bb09fbcc60fa5c3ff551ce9eec1befd7","9f164fa6bb09fbcc60fa5c3ff551ce9eec1befd7",{"version":451,"is_range":439,"range_type":144,"version_start":440,"version_start_type":441,"version_end":452,"version_end_type":443,"fixed_in":9},">= 270a1c3de47e49dd2fc18f48e46b101e48050e78, \u003C d3a5f2871adc0c61c61869f37f3e697d97f03d8c","d3a5f2871adc0c61c61869f37f3e697d97f03d8c",{"version":454,"is_range":132,"range_type":144,"version_start":454,"version_start_type":441,"version_end":454,"version_end_type":441,"fixed_in":9},"6.5",{"ecosystem":9,"name":456,"vendor":434,"product":457,"cpe_part":458,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":459},"linux kernel","linux_kernel","o",[460,464,468,472,474,476,478,480],{"version":461,"is_range":439,"range_type":462,"version_start":454,"version_start_type":441,"version_end":463,"version_end_type":443,"fixed_in":9},"gte6.5_lt6.6.99","cpe","6.6.99",{"version":465,"is_range":439,"range_type":462,"version_start":466,"version_start_type":441,"version_end":467,"version_end_type":443,"fixed_in":9},"gte6.7_lt6.12.39","6.7","6.12.39",{"version":469,"is_range":439,"range_type":462,"version_start":470,"version_start_type":441,"version_end":471,"version_end_type":443,"fixed_in":9},"gte6.13_lt6.15.7","6.13","6.15.7",{"version":473,"is_range":132,"range_type":462,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.16:rc1",{"version":475,"is_range":132,"range_type":462,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.16:rc2",{"version":477,"is_range":132,"range_type":462,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.16:rc3",{"version":479,"is_range":132,"range_type":462,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.16:rc4",{"version":481,"is_range":132,"range_type":462,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.16:rc5"]