Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel metadata but forget to zero unused rxhash fields. This may leak information to another side. Fixing this by zeroing the unused hash fields.
References
- https://git.kernel.org/stable/c/b2284768c6b32aa224ca7d0ef0741beb434f03aa
- https://git.kernel.org/stable/c/b625d231c66a6041e98817ffc944bf6e4c45b2e3
FAQ
What is CVE-2025-40236?
CVE-2025-40236 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel met...
How severe is CVE-2025-40236?
CVSS scoring is not yet available for CVE-2025-40236. Check NVD for updates.
Is there a patch for CVE-2025-40236?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.