CVE-2025-38413: virtio-net: xsk: rx: fix the frame's length check
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: xsk: rx: fix the frame's length check
When calling buftoxdp, the len argument is the frame data's length without virtio header's length (vi->hdrlen). We check that len with
xskpoolgetrxframesize() + vi->hdrlen
to ensure the provided len does not larger than the allocated chunk size. The additional vi->hdrlen is because in virtnetaddrecvbufxsk, we use part of XDPPACKETHEADROOM for virtio header and ask the vhost to start placing data from
hardstart + XDPPACKETHEADROOM - vi->hdrlen not hardstart + XDPPACKETHEADROOM
But the first buffer has virtioheader, so the maximum frame's length in the first buffer can only be
xskpoolgetrxframesize() not xskpoolgetrxframesize() + vi->hdrlen
like in the current check.
This commit adds an additional argument to buftoxdp differentiate between the first buffer and other ones to correctly calculate the maximum frame's length.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38413?
CVE-2025-38413 has been classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2025-38413?
To fix CVE-2025-38413, update your Linux kernel to the latest version where this vulnerability has been addressed.
What systems are affected by CVE-2025-38413?
CVE-2025-38413 affects the Linux kernel, particularly versions that utilize the virtio-net networking stack.
What is the impact of CVE-2025-38413?
The impact of CVE-2025-38413 includes potential memory corruption and denial of service in network processing.
Is CVE-2025-38413 being actively exploited?
As of now, there are no public reports indicating active exploitation of CVE-2025-38413.