CVE-2025-38120 (GCVE-0-2025-38120)
Vulnerability from cvelistv5
Published
2025-07-03 08:35
Modified
2026-08-05 11:59
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2: fix initial map fill If the first field doesn't cover the entire start map, then we must zero out the remainder, else we leak those bits into the next match round map. The early fix was incomplete and did only fix up the generic C implementation. A followup patch adds a test case to nft_concat_range.sh.
Impacted products
Vendor Product Version
Linux Linux Version: 77bf0c4ab928ca4c9a99311f4f70ba0c17fecba9
Version: 957a4d1c4c5849e4515c9fb4db21bf85318103dc
Version: 9625c46ce6fd4f922595a4b32b1de5066d70464f
Version: 69b6a67f7052905e928d75a0c5871de50e686986
Version: 791a615b7ad2258c560f91852be54b0480837c93
Version: 791a615b7ad2258c560f91852be54b0480837c93
Version: 791a615b7ad2258c560f91852be54b0480837c93
Version: 8058c88ac0df21239daee54b5934d5c80ca9685f
Version: 5.15.165   
Version: 6.1.103   
Version: 6.6.44   
Version: 6.10.3   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T17:34:21.242Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/netfilter/nft_set_pipapo_avx2.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "8164d0efaf370c425dc69a1e8216940d09e7de0c",
              "status": "affected",
              "version": "77bf0c4ab928ca4c9a99311f4f70ba0c17fecba9",
              "versionType": "git"
            },
            {
              "lessThan": "b5ad58285f9217d68cd5ea2ad86ce254a3fe7c4d",
              "status": "affected",
              "version": "957a4d1c4c5849e4515c9fb4db21bf85318103dc",
              "versionType": "git"
            },
            {
              "lessThan": "90bc7f5a244aadee4292b28098b7c98aadd4b3aa",
              "status": "affected",
              "version": "9625c46ce6fd4f922595a4b32b1de5066d70464f",
              "versionType": "git"
            },
            {
              "lessThan": "39bab2d3517b5b50c609b4f8c66129bf619fffa0",
              "status": "affected",
              "version": "69b6a67f7052905e928d75a0c5871de50e686986",
              "versionType": "git"
            },
            {
              "lessThan": "251496ce1728c9fd47bd2b20a7b21b20b9a020ca",
              "status": "affected",
              "version": "791a615b7ad2258c560f91852be54b0480837c93",
              "versionType": "git"
            },
            {
              "lessThan": "8068e1e42b46518ce680dc6470bcd710efc3fa0a",
              "status": "affected",
              "version": "791a615b7ad2258c560f91852be54b0480837c93",
              "versionType": "git"
            },
            {
              "lessThan": "ea77c397bff8b6d59f6d83dae1425b08f465e8b5",
              "status": "affected",
              "version": "791a615b7ad2258c560f91852be54b0480837c93",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8058c88ac0df21239daee54b5934d5c80ca9685f",
              "versionType": "git"
            },
            {
              "lessThan": "5.15.186",
              "status": "affected",
              "version": "5.15.165",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1.142",
              "status": "affected",
              "version": "6.1.103",
              "versionType": "semver"
            },
            {
              "lessThan": "6.6.94",
              "status": "affected",
              "version": "6.6.44",
              "versionType": "semver"
            },
            {
              "lessThan": "6.11",
              "status": "affected",
              "version": "6.10.3",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/netfilter/nft_set_pipapo_avx2.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "lessThan": "6.11",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.186",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.142",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.94",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.34",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.15.*",
              "status": "unaffected",
              "version": "6.15.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.16",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.186",
                  "versionStartIncluding": "5.15.165",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.142",
                  "versionStartIncluding": "6.1.103",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.94",
                  "versionStartIncluding": "6.6.44",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.34",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15.3",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.10.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_set_pipapo_avx2: fix initial map fill\n\nIf the first field doesn\u0027t cover the entire start map, then we must zero\nout the remainder, else we leak those bits into the next match round map.\n\nThe early fix was incomplete and did only fix up the generic C\nimplementation.\n\nA followup patch adds a test case to nft_concat_range.sh."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The buggy result-map initialization is in `nft_pipapo_avx2_lookup()`, the nftables set lookup invoked on the packet-processing datapath for every packet traversing a rule that references a concat/range set. A remote unauthenticated attacker triggers and exploits the stale-bit condition purely by sending crafted packet sequences to the filtering host.\nAC:L - The attacker controls both sides: one packet causes a match at a high rule index that leaves bits in the untouched tail of the per-CPU scratch map, and the next packet reads those bits as spurious candidates. AVX2 pipapo is the default set backend on x86-64 and the required set shape (first field smaller than the widest field) is the common `addr . port-range` concatenation.\nPR:N - No credentials or privileges are needed \u2014 merely sending packets that are processed by the victim\u0027s nftables ruleset reaches the vulnerable lookup. The set and ruleset already exist as part of the vulnerable configuration.\nUI:N - The lookup runs automatically in softirq context on packet receive; no action by any local user or administrator is required.\nS:U - The incorrect matching and its consequences remain within the kernel/netfilter security authority of the affected host; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - False-positive set matches let packets take the wrong verdict path, bypassing the intended packet filter so an attacker reaches services and data the ruleset was configured to protect. Wrong element selection in a `map`/`vmap` set also leaks the wrong association\u0027s action to attacker-observable traffic.\nI:H - The bug causes the kernel to apply the wrong verdict, NAT target, or map value to attacker traffic, defeating the configured security policy and permitting unauthorized modification of data on services that should have been unreachable.\nA:L - There is no memory corruption, crash, or hang; however, spurious matches against drop/blocklist sets misclassify legitimate traffic, degrading availability of the protected services rather than fully denying the system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:59:43.745Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8164d0efaf370c425dc69a1e8216940d09e7de0c"
        },
        {
          "url": "https://git.kernel.org/stable/c/b5ad58285f9217d68cd5ea2ad86ce254a3fe7c4d"
        },
        {
          "url": "https://git.kernel.org/stable/c/90bc7f5a244aadee4292b28098b7c98aadd4b3aa"
        },
        {
          "url": "https://git.kernel.org/stable/c/39bab2d3517b5b50c609b4f8c66129bf619fffa0"
        },
        {
          "url": "https://git.kernel.org/stable/c/251496ce1728c9fd47bd2b20a7b21b20b9a020ca"
        },
        {
          "url": "https://git.kernel.org/stable/c/8068e1e42b46518ce680dc6470bcd710efc3fa0a"
        },
        {
          "url": "https://git.kernel.org/stable/c/ea77c397bff8b6d59f6d83dae1425b08f465e8b5"
        }
      ],
      "title": "netfilter: nf_set_pipapo_avx2: fix initial map fill",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-38120",
    "datePublished": "2025-07-03T08:35:27.233Z",
    "dateReserved": "2025-04-16T04:51:23.986Z",
    "dateUpdated": "2026-08-05T11:59:43.745Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…