In the Linux kernel, the following vulnerability has been resolved:
vsock/vmci: Clear the vmci transport packet properly when initializing it
In vmcitransportpacketinit memset the vmcitransport_packet before populating the fields to avoid any uninitialised data being left in the structure.
[
{
"id": "CVE-2025-38403-08a3ce91",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2d44723a091bc853272e1a51a488a3d22b80be5e",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-199b0fd0",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@19c2cc01ff9a8031398a802676ffb0f4692dd95d",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-328332eb",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@75705b44e0b9aaa74f4c163d93d388bcba9e386a",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-349cb4f1",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@223e2288f4b8c262a864e2c03964ffac91744cd5",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38403-46ebaa76",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0a01021317375b8d1895152f544421ce49299eb1",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38403-599fc2cc",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e9a673153d578fd439919a24e99851b2f87ecbce",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-65ee7885",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2d44723a091bc853272e1a51a488a3d22b80be5e",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38403-7414c9e7",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@75705b44e0b9aaa74f4c163d93d388bcba9e386a",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38403-8598296a",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1c1bcb0e78230f533b4103e8cf271d17c3f469f0",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38403-c1e1d488",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@223e2288f4b8c262a864e2c03964ffac91744cd5",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-ddbb8bc8",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@94d0c326cb3ee6b0f8bd00e209550b93fcc5c839",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38403-de8ea4e7",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1c1bcb0e78230f533b4103e8cf271d17c3f469f0",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-e8f4cdce",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0a01021317375b8d1895152f544421ce49299eb1",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-ea7dd69b",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@19c2cc01ff9a8031398a802676ffb0f4692dd95d",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38403-ec80ba5c",
"deprecated": false,
"digest": {
"length": 1608.0,
"function_hash": "230506090828802566697470165162974116031"
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c",
"function": "vmci_transport_packet_init"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@94d0c326cb3ee6b0f8bd00e209550b93fcc5c839",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38403-eeb92dda",
"deprecated": false,
"digest": {
"line_hashes": [
"306252547440540809570953692060314596553",
"270734516384023756063334295306678109936",
"115265308515177128950666537152676185615",
"309850194151335189164867706269052573227",
"215315714222447821683381740208363889503",
"154955457476030216306475913233982712197",
"286959540515324812092975353909024599799",
"14640067358457592990753636383645234059",
"61925894921569151518797173359309044188"
],
"threshold": 0.9
},
"target": {
"file": "net/vmw_vsock/vmci_transport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e9a673153d578fd439919a24e99851b2f87ecbce",
"signature_version": "v1",
"signature_type": "Line"
}
]