Unrated severityNVD Advisory· Published Jul 10, 2025· Updated Nov 3, 2025
seg6: Fix validation of nexthop addresses
CVE-2025-38310
Description
In the Linux kernel, the following vulnerability has been resolved:
seg6: Fix validation of nexthop addresses
The kernel currently validates that the length of the provided nexthop address does not exceed the specified length. This can lead to the kernel reading uninitialized memory if user space provided a shorter length than the specified one.
Fix by validating that the provided length exactly matches the specified one.
Affected products
2- Linux/Linuxv5Range: 4.14
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- git.kernel.org/stable/c/668923c474608dd9ebce0fbcc41bd8a27aa73dd6mitre
- git.kernel.org/stable/c/7632fedb266d93ed0ed9f487133e6c6314a9b2d1mitre
- git.kernel.org/stable/c/cd4cd09810211fa23609c5c1018352e9e1cd8e5amitre
- git.kernel.org/stable/c/cef33a86bcb04ecf4dc10c56f6c42ee9d1c54bacmitre
- git.kernel.org/stable/c/d2507aeea45b3c5aa24d5daae0cf3db76895c0b7mitre
- git.kernel.org/stable/c/d5d9fd13bc19a3f9f2a951c5b6e934d84205789emitre
News mentions
0No linked articles in our index yet.