CVE-2025-38166 is a kernel panic vulnerability in the Linux kernel's BPF and KTLS components, specifically affecting Debian and Ubuntu distributions. It occurs when a BPF program modifies message size, leading to an incorrect rollback mechanism during corking, which can cause a system crash. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local privileges. The primary impact is a denial of service (system crash), with no impact on confidentiality or integrity. There is no known active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. However, it has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.20, < 6.1.142CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.94CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.34CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.15.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026bpf: fix ktls panic with sockmap
Jul 8, 2025kernel: bpf: fix ktls panic with sockmap
Jul 3, 2025