NONE · 0

CVE-2025-40236

In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel met...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel metadata but forget to zero unused rxhash fields. This may leak information to another side. Fixing this by zeroing the unused hash fields.

References

FAQ

What is CVE-2025-40236?

CVE-2025-40236 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel met...

How severe is CVE-2025-40236?

CVSS scoring is not yet available for CVE-2025-40236. Check NVD for updates.

Is there a patch for CVE-2025-40236?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.