CVE-2025-38608: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
Published Aug 19, 2025
·Updated
bpf, ktls: Fix data corruption when using bpfmsgpopdata() in ktls
Affected Software
13 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=5.0<5.4.297
Linux Linux kernel>=5.5<5.10.241
Linux Linux kernel>=5.11<5.15.190
Linux Linux kernel>=5.16<6.1.148
Linux Linux kernel>=6.2<6.6.102
Linux Linux kernel>=6.7<6.12.42
Linux Linux kernel>=6.13<6.15.10
Linux Linux kernel>=6.16<6.16.1
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.96.2-2
Microsoft azl3 kernel 6.6.96.2-1
Microsoft cbl2 kernel 5.15.186.1-1
Event History
Aug 19, 2025
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·02:59 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:59 AM
DescriptionSeverity
Updated
via Microsoft·09:59 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38608?
The severity of CVE-2025-38608 is rated as medium due to the potential for data corruption in the Linux kernel when using bpf_msg_pop_data() in ktls.
2
How do I fix CVE-2025-38608?
To fix CVE-2025-38608, upgrade to the newest patched version of the Linux kernel that addresses this specific vulnerability.
3
What systems are affected by CVE-2025-38608?
CVE-2025-38608 affects the Linux kernel across various distributions that implement the vulnerable functions within their networking stack.
4
What specific issue does CVE-2025-38608 address?
CVE-2025-38608 addresses data corruption issues when sending plaintext data using bpf_msg_pop_data() in the ktls implementation.
5
Is CVE-2025-38608 easy to exploit?
Exploitation of CVE-2025-38608 may require specific conditions to be met, making it moderately challenging for attackers.