CVE-2025-38403

In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: Clear the vmci transport packet properly when initializing it In vmci_transport_packet_init memset the vmci_transport_packet before populating the fields to avoid any uninitialised data being left in the structure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

23 Dec 2025, 19:42

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0a01021317375b8d1895152f544421ce49299eb1 - () https://git.kernel.org/stable/c/0a01021317375b8d1895152f544421ce49299eb1 - Patch
References () https://git.kernel.org/stable/c/19c2cc01ff9a8031398a802676ffb0f4692dd95d - () https://git.kernel.org/stable/c/19c2cc01ff9a8031398a802676ffb0f4692dd95d - Patch
References () https://git.kernel.org/stable/c/1c1bcb0e78230f533b4103e8cf271d17c3f469f0 - () https://git.kernel.org/stable/c/1c1bcb0e78230f533b4103e8cf271d17c3f469f0 - Patch
References () https://git.kernel.org/stable/c/223e2288f4b8c262a864e2c03964ffac91744cd5 - () https://git.kernel.org/stable/c/223e2288f4b8c262a864e2c03964ffac91744cd5 - Patch
References () https://git.kernel.org/stable/c/2d44723a091bc853272e1a51a488a3d22b80be5e - () https://git.kernel.org/stable/c/2d44723a091bc853272e1a51a488a3d22b80be5e - Patch
References () https://git.kernel.org/stable/c/75705b44e0b9aaa74f4c163d93d388bcba9e386a - () https://git.kernel.org/stable/c/75705b44e0b9aaa74f4c163d93d388bcba9e386a - Patch
References () https://git.kernel.org/stable/c/94d0c326cb3ee6b0f8bd00e209550b93fcc5c839 - () https://git.kernel.org/stable/c/94d0c326cb3ee6b0f8bd00e209550b93fcc5c839 - Patch
References () https://git.kernel.org/stable/c/e9a673153d578fd439919a24e99851b2f87ecbce - () https://git.kernel.org/stable/c/e9a673153d578fd439919a24e99851b2f87ecbce - Patch
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Linux
Debian
Debian debian Linux
Linux linux Kernel

03 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html -
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: vsock/vmci: borre el paquete de transporte vmci correctamente al inicializarlo. En vmci_transport_packet_init, configure el vmci_transport_packet antes de completar los campos para evitar que queden datos sin inicializar en la estructura.

25 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-25 14:15

Updated : 2025-12-23 19:42


NVD link : CVE-2025-38403

Mitre link : CVE-2025-38403

CVE.ORG link : CVE-2025-38403


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel