CVE-2025-38120
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/07/2025
Last modified:
03/07/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: nf_set_pipapo_avx2: fix initial map fill<br />
<br />
If the first field doesn&#39;t cover the entire start map, then we must zero<br />
out the remainder, else we leak those bits into the next match round map.<br />
<br />
The early fix was incomplete and did only fix up the generic C<br />
implementation.<br />
<br />
A followup patch adds a test case to nft_concat_range.sh.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/251496ce1728c9fd47bd2b20a7b21b20b9a020ca
- https://git.kernel.org/stable/c/39bab2d3517b5b50c609b4f8c66129bf619fffa0
- https://git.kernel.org/stable/c/8068e1e42b46518ce680dc6470bcd710efc3fa0a
- https://git.kernel.org/stable/c/90bc7f5a244aadee4292b28098b7c98aadd4b3aa
- https://git.kernel.org/stable/c/b5ad58285f9217d68cd5ea2ad86ce254a3fe7c4d
- https://git.kernel.org/stable/c/ea77c397bff8b6d59f6d83dae1425b08f465e8b5