CVE Database
/

CVE-2025-40236

Back to search

CVE-2025-40236

Published: Dec 4, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel metadata but forget to zero unused rxhash fields. This may leak information to another side. Fixing this by zeroing the unused hash fields.

VendorProductVersions

Linux

Linux

affected
a2fb4bc4e2a6a031683910d85b278c1d25ae5420 - < b625d231c66a6041e98817ffc944bf6e4c45b2e3
affected
a2fb4bc4e2a6a031683910d85b278c1d25ae5420 - < b2284768c6b32aa224ca7d0ef0741beb434f03aa

Linux

Linux

affected
6.17
unaffected
0 - < 6.17
unaffected
6.17.6 - <= 6.17.*
unaffected
6.18 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now