๐Ÿ” CVE Alert

CVE-2025-39718

UNKNOWN 0.0

vsock/virtio: Validate length in packet header before skb_put()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header before skb_put() When receiving a vsock packet in the guest, only the virtqueue buffer size is validated prior to virtio_vsock_skb_rx_put(). Unfortunately, virtio_vsock_skb_rx_put() uses the length from the packet header as the length argument to skb_put(), potentially resulting in SKB overflow if the host has gone wonky. Validate the length as advertised by the packet header before calling virtio_vsock_skb_rx_put().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 5, 2025
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
baddcc2c71572968cdaeee1c4ab3dc0ad90fa765 < 969b06bd8b7560efb100a34227619e7d318fbe05 71dc9ec9ac7d3eee785cdc986c3daeb821381e20 < ee438c492b2e0705d819ac0e25d04fae758d8f8f 71dc9ec9ac7d3eee785cdc986c3daeb821381e20 < faf332a10372390ce65d0b803888f4b25a388335 71dc9ec9ac7d3eee785cdc986c3daeb821381e20 < 676f03760ca1d69c2470cef36c44dc152494b47c 71dc9ec9ac7d3eee785cdc986c3daeb821381e20 < 0dab92484474587b82e8e0455839eaf5ac7bf894
Linux / Linux
6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/969b06bd8b7560efb100a34227619e7d318fbe05 git.kernel.org: https://git.kernel.org/stable/c/ee438c492b2e0705d819ac0e25d04fae758d8f8f git.kernel.org: https://git.kernel.org/stable/c/faf332a10372390ce65d0b803888f4b25a388335 git.kernel.org: https://git.kernel.org/stable/c/676f03760ca1d69c2470cef36c44dc152494b47c git.kernel.org: https://git.kernel.org/stable/c/0dab92484474587b82e8e0455839eaf5ac7bf894 lists.debian.org: https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-032379.html