Answer in brief
CVE-2025-38413 records a Unknown severity vulnerability in virtio-net: xsk: rx: fix the frame's length check. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a4e7ba7027012f009f22a68bcfde670f9298d3a4 <892f6ed9a4a38bb3360fdff091b9241cfa105b61 || >=a4e7ba7027012f009f22a68bcfde670f9298d3a4 <6013bb6bc24c2cac3f45b37a15b71b232a5b00ff || >=a4e7ba7027012f009f22a68bcfde670f9298d3a4 <5177373c31318c3c6a190383bfd232e6cf565c36 | 892f6ed9a4a38bb3360fdff091b9241cfa105b61, 6013bb6bc24c2cac3f45b37a15b71b232a5b00ff, 5177373c31318c3c6a190383bfd232e6cf565c36 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Jul 25, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio-net: xsk: rx: fix the frame's length check When calling buf_to_xdp, the len argument is the frame data's length without virtio header's length (vi->hdr_len). We check that len with xsk_pool_get_rx_frame_size() + vi->hdr_len to ensure the provided len does not larger than the allocated chunk size. The additional vi->hdr_len is because in virtnet_add_recvbuf_xsk, we use part of XDP_PACKET_HEADROOM for virtio header and ask the vhost to start placing data from hard_start + XDP_PACKET_HEADROOM - vi->hdr_len not hard_start + XDP_PACKET_HEADROOM But the first buffer has virtio_header, so the maximum frame's length in the first buffer can only be xsk_pool_get_rx_frame_size() not xsk_pool_get_rx_frame_size() + vi->hdr_len like in the current check. This commit adds an additional argument to buf_to_xdp differentiate between the first buffer and other ones to correctly calculate the maximum frame's length.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-38413 records a Unknown severity vulnerability in virtio-net: xsk: rx: fix the frame's length check. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a4e7ba7027012f009f22a68bcfde670f9298d3a4 <892f6ed9a4a38bb3360fdff091b9241cfa105b61 || >=a4e7ba7027012f009f22a68bcfde670f9298d3a4 <6013bb6bc24c2cac3f45b37a15b71b232a5b00ff || >=a4e7ba7027012f009f22a68bcfde670f9298d3a4 <5177373c31318c3c6a190383bfd232e6cf565c36 | 892f6ed9a4a38bb3360fdff091b9241cfa105b61, 6013bb6bc24c2cac3f45b37a15b71b232a5b00ff, 5177373c31318c3c6a190383bfd232e6cf565c36 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Jul 25, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio-net: xsk: rx: fix the frame's length check When calling buf_to_xdp, the len argument is the frame data's length without virtio header's length (vi->hdr_len). We check that len with xsk_pool_get_rx_frame_size() + vi->hdr_len to ensure the provided len does not larger than the allocated chunk size. The additional vi->hdr_len is because in virtnet_add_recvbuf_xsk, we use part of XDP_PACKET_HEADROOM for virtio header and ask the vhost to start placing data from hard_start + XDP_PACKET_HEADROOM - vi->hdr_len not hard_start + XDP_PACKET_HEADROOM But the first buffer has virtio_header, so the maximum frame's length in the first buffer can only be xsk_pool_get_rx_frame_size() not xsk_pool_get_rx_frame_size() + vi->hdr_len like in the current check. This commit adds an additional argument to buf_to_xdp differentiate between the first buffer and other ones to correctly calculate the maximum frame's length.
Quoted source text, attributed separately from HOL analysis.