CVE-2025-38574: pptp: ensure minimal skb length in pptp_xmit()

Published Aug 19, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

pptp: ensure minimal skb length in pptpxmit()

Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data on pppsynctxmung") fixed pppsynctxmunge()

We need a similar fix in pptpxmit(), otherwise we might read uninit data as reported by syzbot.

BUG: KMSAN: uninit-value in pptpxmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193 pptpxmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193 pppchannelbridgeinput drivers/net/ppp/pppgeneric.c:2290 [inline] pppinput+0x1d6/0xe60 drivers/net/ppp/pppgeneric.c:2314 pppoercvcore+0x1e8/0x760 drivers/net/ppp/pppoe.c:379 skbacklogrcv+0x142/0x420 include/net/sock.h:1148 releasesock+0x1d3/0x330 net/core/sock.c:3213 releasesock+0x6b/0x270 net/core/sock.c:3767 pppoesendmsg+0x15d/0xcb0 drivers/net/ppp/pppoe.c:904 socksendmsgnosec net/socket.c:712 [inline] socksendmsg+0x330/0x3d0 net/socket.c:727 syssendmsg+0x893/0xd80 net/socket.c:2566 syssendmsg+0x271/0x3b0 net/socket.c:2620 syssendmmsg+0x2d9/0x7c0 net/socket.c:2709

Affected Software

18 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=2.6.13<5.4.297
Linux Linux kernel>=5.5<5.10.241
Linux Linux kernel>=5.11<5.15.190
Linux Linux kernel>=5.16<6.1.148
Linux Linux kernel>=6.2<6.6.102
Linux Linux kernel>=6.7<6.12.42
Linux Linux kernel>=6.13<6.15.10
Linux Linux kernel>=6.16<6.16.1
Linux Linux kernel=2.6.12
Linux Linux kernel=2.6.12-rc2
Linux Linux kernel=2.6.12-rc3
Linux Linux kernel=2.6.12-rc4
Linux Linux kernel=2.6.12-rc5
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2
Microsoft cbl2 kernel 5.15.186.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch aabc6596ffb3

Event History

Aug 19, 2025
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·03:20 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·10:20 AM
DescriptionSeverity
Updated
via Microsoft·10:20 AM
SeverityAffected Software
Nov 7, 58546
Event
via MITRE·01:29 PM

Frequently Asked Questions

1

What is the severity of CVE-2025-38574?

CVE-2025-38574 is considered a medium severity vulnerability due to the potential for data corruption.

2

How do I fix CVE-2025-38574?

To fix CVE-2025-38574, update the Linux kernel to the latest version that includes the security patch.

3

What impact does CVE-2025-38574 have on affected systems?

CVE-2025-38574 may lead to instability and data integrity issues in systems utilizing the PPTP protocol.

4

Is CVE-2025-38574 exploitable remotely?

CVE-2025-38574 can potentially be exploited remotely if the PPTP service is exposed to untrusted networks.

5

When was CVE-2025-38574 first reported?

CVE-2025-38574 was first reported as resolved with the commit aabc6596ffb3 in the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203