CVE-2025-38403 is a high-severity vulnerability in the Linux kernel, specifically affecting Debian and other Linux distributions. It stems from improper initialization of the vmci_transport_packet structure, potentially leaving uninitialized data. With a CVSS score of 7.8, this local vulnerability allows an attacker with low privileges to achieve high confidentiality, integrity, and availability impacts. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, suggesting no active exploitation. However, community discussion and media coverage indicate moderate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.9, < 5.4.296CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.240CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.187CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.144CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.97CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026kernel: Kernel: Privilege escalation via uninitialized data in vmci transport packet
Jul 25, 2025vsock/vmci: Clear the vmci transport packet properly when initializing it
Jul 8, 2025