In the Linux kernel, the following vulnerability has been resolved:
virtio-net: zero unused hash fields
When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to
initialize the tunnel metadata but forget to zero unused rxhash
fields. This may leak information to another side. Fixing this by
zeroing the unused hash fields.
CVSS
No CVSS.
References
Configurations
No configuration.
History
04 Dec 2025, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-04 16:16
Updated : 2026-04-15 00:35
NVD link : CVE-2025-40236
Mitre link : CVE-2025-40236
CVE.ORG link : CVE-2025-40236
JSON object : View
Products Affected
No product.
CWE
No CWE.
