PT-2025-33788 · Mlx5E+5 · Mlx5E+5
CVE-2025-38590
·
Published
2025-07-23
·
Updated
2026-08-30
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.15.0-rc7 for upstream min debug 2025 05 27 22 44
Description:
A flaw exists in the Linux kernel's
net/mlx5e module related to handling XFRM (eXact Forwarding Path) states during packet decryption. Specifically, if a decrypted packet's XFRM state cannot be found in the xarray, the secpath extension on the skb (socket buffer) is not removed. This results in a zero-length secpath, leading to a crash when functions like xfrm policy check() attempt to access fields within the invalid state pointer. The issue occurs when hardware returns a unique identifier for a decrypted packet's xfrm state, which may have been freed by the time of the lookup.Recommendations:
Update to Linux kernel version 6.15.0-rc7 for upstream min debug 2025 05 27 22 44 or a later version that includes the fix.
Exploit
Fix
Buffer Overflow
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Mlx5E