CVE-2025-38432
MEDIUM EPSS 3.5%
Published Jul 25, 202511mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Published Jul 25, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago
Description
In the Linux kernel, the following vulnerability has been resolved: net: netpoll: Initialize UDP checksum field before checksumming commit f1fce08e63fe ("netpoll: Eliminate redundant assignment") removed the initialization of the UDP checksum, which was wrong and broke netpoll IPv6 transmission due to bad checksumming. udph->check needs to be set before calling csum_ipv6_magic().
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
3.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Affected Products 4
References 2
- git.kernel.org https://git.kernel.org/stable/c/353016ec159f939a380ff6746476a779367ba9a3
- git.kernel.org https://git.kernel.org/stable/c/f5990207026987a353d5a95204c4d9cb725637fd
Remediation
- git.kernel.org https://git.kernel.org/stable/c/353016ec159f939a380ff6746476a779367ba9a3
- git.kernel.org https://git.kernel.org/stable/c/f5990207026987a353d5a95204c4d9cb725637fd