CVE-2025-38413

MEDIUM

Linux Kernel 6.11-6.12.36, 6.13-6.14.5 - Buffer Overflow in virtio-net XSK RX Frame Length Check

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: virtio-net: xsk: rx: fix the frame's length check When calling buf_to_xdp, the len argument is the frame data's length without virtio header's length (vi->hdr_len). We check that len with xsk_pool_get_rx_frame_size() + vi->hdr_len to ensure the provided len does not larger than the allocated chunk size. The additional vi->hdr_len is because in virtnet_add_recvbuf_xsk, we use part of XDP_PACKET_HEADROOM for virtio header and ask the vhost to start placing data from hard_start + XDP_PACKET_HEADROOM - vi->hdr_len not hard_start + XDP_PACKET_HEADROOM But the first buffer has virtio_header, so the maximum frame's length in the first buffer can only be xsk_pool_get_rx_frame_size() not xsk_pool_get_rx_frame_size() + vi->hdr_len like in the current check. This commit adds an additional argument to buf_to_xdp differentiate between the first buffer and other ones to correctly calculate the maximum frame's length.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 5.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (12)
linux/Kernel 6.11.0 - 6.12.37linux
linux/Kernel 6.13.0 - 6.15.6linux
Linux/Linux < 6.11
Linux/Linux 6.11
Linux/Linux 6.12.37 - 6.12.*
Linux/Linux 6.15.6 - 6.15.*
Linux/Linux 6.16
Linux/Linux a4e7ba7027012f009f22a68bcfde670f9298d3a4 - 5177373c31318c3c6a190383bfd232e6cf565c36
Linux/Linux a4e7ba7027012f009f22a68bcfde670f9298d3a4 - 6013bb6bc24c2cac3f45b37a15b71b232a5b00ff
Linux/Linux a4e7ba7027012f009f22a68bcfde670f9298d3a4 - 892f6ed9a4a38bb3360fdff091b9241cfa105b61
... and 2 more
Published Jul 25, 2025
Tracked Since Feb 18, 2026