PT-2025-37216 · Linux+5 · Linux Kernel+5

Published

2025-07-29

·

Updated

2026-04-20

·

CVE-2025-39758

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A flaw was discovered in the Linux kernel’s RDMA/siw subsystem, specifically within the siw tcp sendpages function. The issue involves an incorrect byte count being used in sendmsg calls, leading to oversized iov iters. This bug was previously benign but has recently caused out-of-bounds crashes due to changes in the slab allocator that disallow sendpage on large kmalloc allocations. The problem arises from discrepancies in iov iter behavior between the MSG SPLICE PAGES and regular copy paths.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

AZL-67157
BDU:2025-15699
CVE-2025-39758
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu