Linux Kernel virtio-net Out-of-Bounds Read Vulnerability

Vulnerability

A vulnerability in the Linux kernel's virtio-net component can lead to an out-of-bounds read. This issue arises in the xdp_linearize_page function, where the length of received data is not properly checked against the allocated buffer size. The oversight can cause unauthorized memory access. The vulnerability has been addressed by implementing the necessary length verification.

Impact

Exploitation of this vulnerability can result in an out-of-bounds read, potentially leading to information disclosure or memory corruption.

Added: Jul 25, 2025, 2:35 PM
Updated: Jul 25, 2025, 7:03 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
0.0
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.