In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_set_pipapo_avx2: fix initial map fill
If the first field doesn't cover the entire start map, then we must zero
out the remainder, else we leak those bits into the next match round map.
The early fix was incomplete and did only fix up the generic C
implementation.
A followup patch adds a test case to nft_concat_range.sh.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Jul 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Thu, 03 Jul 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2: fix initial map fill If the first field doesn't cover the entire start map, then we must zero out the remainder, else we leak those bits into the next match round map. The early fix was incomplete and did only fix up the generic C implementation. A followup patch adds a test case to nft_concat_range.sh. | |
Title | netfilter: nf_set_pipapo_avx2: fix initial map fill | |
References |
|
|

Status: PUBLISHED
Assigner: Linux
Published: 2025-07-03T08:35:27.233Z
Updated: 2025-07-28T04:12:39.824Z
Reserved: 2025-04-16T04:51:23.986Z
Link: CVE-2025-38120

No data.

Status : Awaiting Analysis
Published: 2025-07-03T09:15:26.037
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-38120
