๐Ÿ” CVE Alert

CVE-2025-40236

UNKNOWN 0.0

virtio-net: zero unused hash fields

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel metadata but forget to zero unused rxhash fields. This may leak information to another side. Fixing this by zeroing the unused hash fields.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Dec 4, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
a2fb4bc4e2a6a031683910d85b278c1d25ae5420 < b625d231c66a6041e98817ffc944bf6e4c45b2e3 a2fb4bc4e2a6a031683910d85b278c1d25ae5420 < b2284768c6b32aa224ca7d0ef0741beb434f03aa
Linux / Linux
6.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b625d231c66a6041e98817ffc944bf6e4c45b2e3 git.kernel.org: https://git.kernel.org/stable/c/b2284768c6b32aa224ca7d0ef0741beb434f03aa