
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39758 is a vulnerability discovered in the Linux kernel's RDMA/siw component, specifically in the TCP sendmsg byte count handling in siwtcpsendpages. The issue was identified and disclosed on September 11, 2025, affecting the Linux kernel's network stack (NVD).
The vulnerability stems from an implementation flaw in the siwtcpsendpages function where oversized ioviters and tcpsendmsg calls were being made. The issue became problematic with recent slab allocator changes that disallow sendpage on large kmalloc allocations, leading to out-of-bounds crashes due to differences in ioviter behavior between MSGSPLICE_PAGES and regular copy paths (NVD).
The vulnerability can result in out-of-bounds crashes in the Linux kernel when specific conditions are met, particularly affecting systems using the RDMA/siw component. This could potentially lead to system instability and denial of service conditions (NVD).
The issue has been resolved by properly setting the ioviter's byte count and sending the correct byte count to tcpsendmsg_locked. The fix involves adjusting how the byte count is handled in the affected code paths (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."