PT-2025-25781 · Linux+5 · Linux Kernel+5

Published

2025-05-08

·

Updated

2026-04-20

·

CVE-2025-38006

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel's MCTP implementation has been resolved. The issue occurs in the mctp dump addrinfo function when ifa index is accessed without proper initialization, potentially leading to comparison with uninitialized memory. This can be reproduced using syzkaller or by running specific commands like "ip addr show" with busybox. Existing userspace programs that dump MCTP addresses are expected to pass a valid ifa index value.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-09042
CVE-2025-38006
ECHO-F2A9-002D-AF9E
OESA-2025-2077
OESA-2025-2078
OESA-2025-2079
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03272-1
SUSE-SU-2025:03290-1
SUSE-SU-2025:03301-1
SUSE-SU-2025:03382-1
SUSE-SU-2025:03602-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20653-1
SUSE-SU-2025:20669-1
SUSE-SU-2025:20739-1
SUSE-SU-2025:20756-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_03272-1
SUSE-SU-2025_03290-1
SUSE-SU-2025_03301-1
SUSE-SU-2025_03382-1
USN-7699-1
USN-7699-2
USN-7721-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu