Information Leak Vulnerability in Linux Kernel Affecting Virtio Network Functionality
CVE-2025-40236

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 December 2025

What is CVE-2025-40236?

In the Linux kernel, a significant vulnerability exists in the 'virtio-net' component that can lead to information leakage during the negotiation of Generic Segmentation Offload (GSO) tunnels. The function 'virtio_net_hdr_tnl_from_skb()' is responsible for initializing tunnel metadata, but it fails to properly zero out unused receive hash fields. This oversight may inadvertently expose sensitive information to unauthorized parties on the network. The issue has been addressed by ensuring that all unused hash fields are appropriately zeroed, thereby enhancing data security and preserving user privacy.

Affected Version(s)

Linux a2fb4bc4e2a6a031683910d85b278c1d25ae5420

Linux a2fb4bc4e2a6a031683910d85b278c1d25ae5420

Linux 6.17

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40236 : Information Leak Vulnerability in Linux Kernel Affecting Virtio Network Functionality