Home

Description

In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel metadata but forget to zero unused rxhash fields. This may leak information to another side. Fixing this by zeroing the unused hash fields.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-04 | Updated 2025-12-04 | Assigner Linux

Product status

Default status
unaffected

a2fb4bc4e2a6a031683910d85b278c1d25ae5420 (git) before b625d231c66a6041e98817ffc944bf6e4c45b2e3
affected

a2fb4bc4e2a6a031683910d85b278c1d25ae5420 (git) before b2284768c6b32aa224ca7d0ef0741beb434f03aa
affected

Default status
affected

6.17
affected

Any version before 6.17
unaffected

6.17.6 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/b625d231c66a6041e98817ffc944bf6e4c45b2e3

git.kernel.org/...c/b2284768c6b32aa224ca7d0ef0741beb434f03aa

cve.org (CVE-2025-40236)

nvd.nist.gov (CVE-2025-40236)