PT-2025-18943 · Linux+9 · Linux Kernel+9

Published

2025-04-25

·

Updated

2026-04-20

·

CVE-2025-37799

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns the vmxnet3 driver's XDP handling, which is buggy for packet sizes between 128 and 3k bytes. This bug can cause MTU-related connectivity issues, and in some cases, it can lead to the leakage of uninitialized kernel data onto the wire. The problem was noticed when using Cilium's service load-balancing with vmxnet3 as the NIC, where a simple curl request to an HTTP backend service resulted in overly large packet sizes. The affected packets were padded with uninitialized data, which could include user or payload data from prior processed packets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

ALSA-2025:10371
ALSA-2025:10379
BDU:2026-02461
CVE-2025-37799
ECHO-2A8D-08E2-BD55
INFSA-2025_10379
MGASA-2025-0182
MGASA-2025-0183
OESA-2025-1511
OESA-2025-1512
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
RHSA-2025:10371
RHSA-2025:10379
RHSA-2025:10674
RHSA-2025_10379
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:20343-1
SUSE-SU-2025:20344-1
SUSE-SU-2025:20354-1
SUSE-SU-2025:20355-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu