CVE-2025-39758
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39758 is a vulnerability discovered in the Linux kernel's RDMA/siw component, specifically in the TCP sendmsg byte count handling in siwtcpsendpages. The issue was identified and disclosed on September 11, 2025, affecting the Linux kernel's network stack (NVD).

Technical details

The vulnerability stems from an implementation flaw in the siwtcpsendpages function where oversized ioviters and tcpsendmsg calls were being made. The issue became problematic with recent slab allocator changes that disallow sendpage on large kmalloc allocations, leading to out-of-bounds crashes due to differences in ioviter behavior between MSGSPLICE_PAGES and regular copy paths (NVD).

Impact

The vulnerability can result in out-of-bounds crashes in the Linux kernel when specific conditions are met, particularly affecting systems using the RDMA/siw component. This could potentially lead to system instability and denial of service conditions (NVD).

Mitigation and workarounds

The issue has been resolved by properly setting the ioviter's byte count and sending the correct byte count to tcpsendmsg_locked. The fix involves adjusting how the byte count is handled in the affected code paths (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management