Kernel memory disclosure and corruption via virtio lengths
Published Jul 25, 2025 · Updated Aug 5, 2026
Out-of-bounds memory access in Linux allows attackers controlling a virtio backend to disclose kernel memory, corrupt it, or crash the guest. The xdp_linearize_page path trusts used-ring lengths and copies subsequent receive buffers without checking each length against its allocated size, permitting oversized reads and unsigned-wraparound writes. Exploitation requires an XDP-enabled virtio-net guest and control of its backend; remote packets, guest credentials, and user interaction are insufficient and unnecessary.
Summary
What happened
Out-of-bounds memory access in Linux allows attackers controlling a virtio backend to disclose kernel memory, corrupt it, or crash the guest. The xdp_linearize_page path trusts used-ring lengths and copies subsequent receive buffers without checking each length against its allocated size, permitting oversized reads and unsigned-wraparound writes. Exploitation requires an XDP-enabled virtio-net guest and control of its backend; remote packets, guest credentials, and user interaction are insufficient and unnecessary.
The record
- CVE
- CVE-2025-38375
- Published
- Jul 25, 2025
- Updated
- Aug 5, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- CWE-125, T1499.004
- Attack vector
- local
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jul 25, 2025CVE publishedPublication date reported by the CVE source.
- Aug 5, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=4.14
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <11f2d0e8be2b5e784ac45fa3da226492c3e506d8
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <315dbdd7cdf6aa533829774caaf4d25f1fd20e73
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <6aca3dad2145e864dfe4d1060f45eb1bac75dd58
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <773e95c268b5d859f51f7547559734fd2a57660c
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <80b971be4c37a4d23a7f1abc5ff33dc7733d649b
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <982beb7582c193544eb9c6083937ec5ac1c9d651
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <bc68bc3563344ccdc57d1961457cdeecab8f81ef
- Affected versionversion=4941d472bf95b4345d6e38906fcf354e74afa311 <ddc8649d363141fb3371dd81a73e1cb4ef8ed1e1
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo