Linux Kernel Vmxnet3 XDP RXQ Info Unregistration Vulnerability

Vulnerability

A vulnerability in the Linux kernel's vmxnet3 driver has been addressed, concerning the improper handling of XDP (eXpress Data Path) receive queue information during the reset process. The issue arose because the vmxnet3_reset_work() function did not call vmxnet3_rq_destroy(), leading to a warning message about the missing unregistration. This vulnerability could potentially cause issues with XDP functionality in virtualized environments.

Impact

The vulnerability could lead to warnings about missing unregistration, which may indicate improper management of resources related to XDP, potentially causing issues in performance or functionality in environments that rely on XDP for packet processing.

Remediation

Users can apply the latest patches from the official Linux kernel repository to address this vulnerability. The specific commits that resolve this issue can be found in the Linux kernel Git repository.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.