PT-2025-33765 · Linux+7 · Linux Kernel+7
Scott Mayhew
·
Publicado
2025-07-29
·
Atualizado
2026-04-20
·
CVE-2025-38566
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A security issue was identified in the Linux kernel related to the handling of server-side TLS alerts within the sunrpc component. The
tls alert recv() function incorrectly assumed it could read data from the message iterator's kvec. This occurs because the kTLS implementation splits TLS record payloads between a control message buffer and a payload buffer. The patch addresses this by reworking how control messages are set up and used by sock recvmsg(). Specifically, the kTLS layer now returns an error upon encountering a TLS control message, allowing NFS to set up a kvec-backed message buffer to read the control message, such as a TLS alert.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Buffer Overflow
Improper Check for Exceptional Conditions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu