Junglewise Threat Intelligence

CVE-2025-38718: Linux Kernel uninitialized memory access in SCTP GSO packet handling

CVE-2025-38718 · Severity: high · CVSS 7.8 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially access sensitive information. The issue occurs when the system processes specific types of network traffic using the SCTP protocol. This could impact the stability and security of servers or devices running affected versions of Linux.

Technical details

A vulnerability in the Linux kernel's SCTP implementation (net/sctp/input.c) arises from improper handling of cloned Generic Segmentation Offload (GSO) packets. When a head socket buffer (skb) is cloned, it continues to share fragment buffers in the fraglist with the original skb, making direct access to these fragments unsafe. This leads to uninitialized memory access in functions such as sctp_inq_pop and sctp_assoc_bh_rcv. The fix involves ensuring cloned GSO packets are linearized in sctp_rcv() before processing. The vulnerability is reachable by a local user and has been addressed in multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 90017accff61 to d0194e391bb493aa6cec56d177b14df6b29188d5

Timeline

  • 2025-09-04: advisory: NVD publication date
  • 2025-08-28: patched: Commit 03d0cc6889e02420125510b5444b570f4bbf53d5 applied to stable tree

References

Related threats