PT-2025-35991 · Linux+9 · Linux Kernel+9

Syzbot

·

Published

2025-08-07

·

Updated

2026-05-26

·

CVE-2025-38718

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to the handling of cloned GSO (Generic Segmentation Offload) packets within the SCTP (Stream Control Transmission Protocol) stack. Specifically, a cloned head skb (socket buffer) continues to share frag skbs (fragment socket buffers) in its fraglist with the original head skb, leading to potential use-of-uninitialized-memory issues. This condition was identified through syzbot reports, indicating potential bugs in functions such as sctp inq pop, sctp assoc bh rcv, sctp inq push, and sctp backlog rcv.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use of Uninitialized Resource

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

ALSA-2025:16880
ALSA-2025:16919
ALSA-2025:16920
ALSA-2025:17396
AZL-66788
AZL-73893
BDU:2026-03072
CESA-2025_16919
CESA-2025_16920
CVE-2025-38718
DLA-4327-1
ECHO-4E7F-99E9-5DBF
INFSA-2025_16880
INFSA-2025_16919
INFSA-2025_16920
MGASA-2025-0234
MGASA-2025-0235
OPENSUSE-SU-2025:20091-1
RHSA-2025:19223
RHSA-2025:19224
RHSA-2025:21091
RHSA-2025:21136
RHSA-2025_16880
RHSA-2025_16919
RHSA-2025_16920
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4189-1
SUSE-SU-2025:4301-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu