Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/cesa - Handle zero-length skcipher requests Do not access random memory for zero-length skcipher requests. Just return 0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.2, < 5.4.295 |
| Debian | Debian Linux | 11.0 |
References
- https://git.kernel.org/stable/c/32d3e8049a8b60f18c5c39f5931bfb1130ac11c9Patch
- https://git.kernel.org/stable/c/5e9666ac8b94c978690f937d59170c5237bd2c45Patch
- https://git.kernel.org/stable/c/7894694b5d5b2ecfd7fb081d6f60b9e169ab4d13Patch
- https://git.kernel.org/stable/c/78ea1ff6cb413a03ff6f7af4e28e24b4461a0965Patch
- https://git.kernel.org/stable/c/8a4e047c6cc07676f637608a9dd675349b5de0a7Patch
- https://git.kernel.org/stable/c/c064ae2881d839709bd72d484d5f2af157f46024Patch
- https://git.kernel.org/stable/c/c9610dda42bd382a96f97e68825cb5f66cd9e1dcPatch
- https://git.kernel.org/stable/c/e1cc69da619588b1488689fe3535a0ba75a2b0e7Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
FAQ
What is CVE-2025-38173?
CVE-2025-38173 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/cesa - Handle zero-length skcipher requests Do not access random memory for zero-length skcipher requests. Just re...
How severe is CVE-2025-38173?
CVE-2025-38173 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38173?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.