CVE-2025-38413 | Linux Kernel up to 6.12.36/6.15.5/6.16-rc4 virtio-net xsk_pool_get_rx_frame_size len buffer overflow (Nessus ID 271193 / WID-SEC-2025-1653)
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.36/6.15.5/6.16-rc4. The affected element is the function xsk_pool_get_rx_frame_size of the component virtio-net. Performing manipulation of the argument len results in buffer overflow.
This vulnerability is identified as CVE-2025-38413. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.