virtio-net: ensure the received length does not exceed allocated size
Summary
| CVE | CVE-2025-38375 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-07-25 13:15:26 UTC |
| Updated | 2026-07-30 06:23:10 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exceed allocated size In xdp_linearize_page, when reading the following buffers from the ring, we forget to check the received length with the true allocate size. This can lead to an out-of-bound read. This commit adds that missing check. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-125
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 773e95c268b5d859f51f7547559734fd2a57660c git | Not specified |
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 ddc8649d363141fb3371dd81a73e1cb4ef8ed1e1 git | Not specified |
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 982beb7582c193544eb9c6083937ec5ac1c9d651 git | Not specified |
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 6aca3dad2145e864dfe4d1060f45eb1bac75dd58 git | Not specified |
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 80b971be4c37a4d23a7f1abc5ff33dc7733d649b git | Not specified |
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 bc68bc3563344ccdc57d1961457cdeecab8f81ef git | Not specified |
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 11f2d0e8be2b5e784ac45fa3da226492c3e506d8 git | Not specified |
| CNA | Linux | Linux | affected 4941d472bf95b4345d6e38906fcf354e74afa311 315dbdd7cdf6aa533829774caaf4d25f1fd20e73 git | Not specified |
| CNA | Linux | Linux | affected 4.14 | Not specified |
| CNA | Linux | Linux | unaffected 4.14 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.297 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.241 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.189 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.144 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.97 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.37 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.15.6 6.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.16 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/315dbdd7cdf6aa533829774caaf4d25f1fd20e73 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/6aca3dad2145e864dfe4d1060f45eb1bac75dd58 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2025/10/msg00008.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Third Party Advisory |
| git.kernel.org/stable/c/ddc8649d363141fb3371dd81a73e1cb4ef8ed1e1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/982beb7582c193544eb9c6083937ec5ac1c9d651 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/80b971be4c37a4d23a7f1abc5ff33dc7733d649b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/773e95c268b5d859f51f7547559734fd2a57660c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/11f2d0e8be2b5e784ac45fa3da226492c3e506d8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2025/10/msg00007.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Third Party Advisory |
| git.kernel.org/stable/c/bc68bc3563344ccdc57d1961457cdeecab8f81ef | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.