CVE-2025-40236 is a Linux kernel vulnerability affecting virtio-net when GSO tunnel is negotiated. It involves a failure to zero unused rxhash fields during tunnel metadata initialization, potentially leading to information leakage. While no CVSS score is available, its FAUCET Risk Score is low at 7/100, and its EPSS score is very low, indicating minimal exploitability. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.17CNA affecteddefault affected | |
| Linux | Linux | >= a2fb4bc4e2a6a031683910d85b278c1d25ae5420, < b2284768c6b32aa224ca7d0ef0741beb434f03aa, >= a2fb4bc4e2a6a031683910d85b278c1d25ae5420, < b625d231c66a6041e98817ffc944bf6e4c45b2e3CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.