PT-2025-33788 · Mlx5E+5 · Mlx5E+5
Published
2025-07-23
·
Updated
2026-04-20
·
CVE-2025-38590
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.15.0-rc7 for upstream min debug 2025 05 27 22 44
Description:
A flaw exists in the Linux kernel's
net/mlx5e module related to handling XFRM (eXact Forwarding Path) states during packet decryption. Specifically, if a decrypted packet's XFRM state cannot be found in the xarray, the secpath extension on the skb (socket buffer) is not removed. This results in a zero-length secpath, leading to a crash when functions like xfrm policy check() attempt to access fields within the invalid state pointer. The issue occurs when hardware returns a unique identifier for a decrypted packet's xfrm state, which may have been freed by the time of the lookup.Recommendations:
Update to Linux kernel version 6.15.0-rc7 for upstream min debug 2025 05 27 22 44 or a later version that includes the fix.
Exploit
Fix
Buffer Overflow
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Mlx5E