Junglewise Threat Intelligence

CVE-2025-39718: Linux Kernel out-of-bounds write in vsock virtio transport

CVE-2025-39718 · Severity: high · CVSS 8.4 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization communication system (vsock) could allow a malicious or compromised host machine to crash or potentially gain unauthorized access to a guest virtual machine. The issue occurs when the guest system processes incoming data packets without properly verifying their size, leading to memory corruption. This could impact the stability and security of virtualized environments and the data they process.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Linux kernel's vsock/virtio transport layer. The function virtio_transport_rx_work() in net/vmw_vsock/virtio_transport.c fails to validate the length field provided in the virtio_vsock_hdr before passing it to skb_put(). A compromised or malicious host can provide a payload length that exceeds the allocated socket buffer (SKB) size, causing a kernel memory overflow. This can result in a denial of service (system crash) or potentially arbitrary code execution within the guest kernel. Patches have been released for various stable kernel branches including 6.1.149, 6.6.103, 6.12.44, and 6.16.4.

Affected products

  • Linux Linux Kernel 6.1.63 to 6.1.149, 6.3 to 6.17 (exclusive)
  • Siemens SIMATIC CN 4100 < V5.0

Timeline

  • 2025-07-17: patched: Initial fix authored by Will Deacon
  • 2025-09-05: advisory: CVE published in NVD

References

Related threats