CVE-2025-38403: vsock/vmci: Clear the vmci transport packet properly when initializing it
In the Linux kernel, the following vulnerability has been resolved:
vsock/vmci: Clear the vmci transport packet properly when initializing it
In vmcitransportpacketinit memset the vmcitransportpacket before populating the fields to avoid any uninitialised data being left in the structure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38403?
CVE-2025-38403 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2025-38403?
To fix CVE-2025-38403, upgrade the Linux kernel to the latest stable version that includes the patch for this vulnerability.
What systems are affected by CVE-2025-38403?
CVE-2025-38403 specifically affects systems running vulnerable versions of the Linux kernel.
What is the nature of the vulnerability in CVE-2025-38403?
CVE-2025-38403 involves improper initialization of the vmci transport packet, potentially leading to uninitialized data issues.
Is CVE-2025-38403 being actively exploited?
As of now, there are no public reports indicating that CVE-2025-38403 is being actively exploited in the wild.