CVE-2025-38166
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38166 is a vulnerability discovered in the Linux kernel related to the BPF (Berkeley Packet Filter) and kTLS (Kernel Transport Layer Security) implementation. The vulnerability was disclosed on July 3, 2025, affecting the Linux kernel's sockmap functionality (NVD, CVE).

Technical details

The vulnerability occurs when calling bpf_exec_tx_verdict(), where the size of msg_pl->sg may increase during BPF program execution of bpf_msg_push_data(). If the BPF program sets cork_bytes and sg.size is smaller than cork_bytes, it returns -ENOSPC and attempts to roll back to non-zero copy logic. During rollback, while msg->msg_iter is reset, msg_pl->sg.size remains increased, causing subsequent executions to exceed the actual size of msg_iter (CVE).

Impact

The vulnerability results in a kernel panic at lib/iov_iter.c:629, potentially causing system crashes and service disruption. This affects systems using BPF programs with kTLS and sockmap functionality (Debian Tracker).

Mitigation and workarounds

Fixed versions have been released for various Linux distributions. Debian has addressed this in version 6.12.35-1 for trixie and 6.12.37-1 for sid. The fix involves modifying the handling of cork_bytes situations to directly use zero-copy logic instead of attempting rollback to non-zero copy logic (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-oem-6.14
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management