FlawAtlas
Search the atlas
CVE-2025-38375 Not scored

virtio-net: ensure the received length does not exceed allocated size

In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exceed allocated size In xdp_linearize_page, when reading the following buffers from the ring, we forget to check the received length with the true allocate size. This can lead to an out-of-bound read. This commit adds that missing check.

Exploit probability 0.2%
Published July 25, 2025
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Linux Kernel
Unknown Unknown

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2025:20081-1
related SUSE-SU-2025:02846-1
related SUSE-SU-2025:02853-1
related SUSE-SU-2025:02923-1
related SUSE-SU-2025:02969-1
related SUSE-SU-2025:02996-1
related SUSE-SU-2025:02997-1
related SUSE-SU-2025:03011-1
related SUSE-SU-2025:03023-1
related SUSE-SU-2025:20577-1
related SUSE-SU-2025:20586-1
related SUSE-SU-2025:20601-1
related SUSE-SU-2025:20602-1
related SUSE-SU-2025:21074-1
related SUSE-SU-2025:21139-1
related SUSE-SU-2025:21179-1
related SUSE-SU-2026:0411-1
related SUSE-SU-2026:0474-1
related SUSE-SU-2026:0496-1
related SUSE-SU-2026:0617-1
related SUSE-SU-2026:0928-1
related SUSE-SU-2026:0961-1
related SUSE-SU-2026:1684-1
related SUSE-SU-2026:1708-1
related SUSE-SU-2026:1718-1
related SUSE-SU-2026:1725-1
related SUSE-SU-2026:1733-1
related SUSE-SU-2026:1765-1
related SUSE-SU-2026:1768-1
related SUSE-SU-2026:1770-1
related SUSE-SU-2026:1771-1
related SUSE-SU-2026:1776-1
related SUSE-SU-2026:1780-1
related SUSE-SU-2026:1790-1
related SUSE-SU-2026:1793-1
related SUSE-SU-2026:1798-1
related SUSE-SU-2026:1804-1
related SUSE-SU-2026:21468-1
related SUSE-SU-2026:21469-1
related SUSE-SU-2026:21470-1
related SUSE-SU-2026:21471-1
related SUSE-SU-2026:21472-1
related SUSE-SU-2026:21479-1
related SUSE-SU-2026:21480-1
related SUSE-SU-2026:21481-1
related SUSE-SU-2026:21487-1
related SUSE-SU-2026:21495-1
related SUSE-SU-2026:21496-1
related SUSE-SU-2026:21497-1
related SUSE-SU-2026:21501-1
related SUSE-SU-2026:21506-1
related SUSE-SU-2026:21507-1
related SUSE-SU-2026:21508-1
related SUSE-SU-2026:21509-1
related SUSE-SU-2026:21510-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-38375

In the Linux kernel, the following vulnerability has been resolved: virtio-net: ensure the received length does not exceed allocated size In xdp_linearize_page, when reading the following buffers from the ring, we forget to check the received length with the true allocate size. This can lead to an out-of-bound read. This commit adds that missing check.

View original source

05 / REFERENCES

Further evidence