LiveActive security incident?Get immediate response
CVE Record

CVE-2025-38608: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls

In the Linux kernel, the following vulnerability has been resolved: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls When sending plaintext data, we initially calculated the corresponding ciphertext length. However, if we later reduced the plaintext data length via socket policy, we failed to recalculate the ciphertext length. This results in transmitting buffers containing uninitialized data during ciphertext transmission. This causes uninitialized bytes to be appended after a complete "Application Data" packet, leading to errors on the receiving end when parsing TLS record.

HighCVSS 8.6Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux kernel flaw can cause systems using kernel TLS with a specific BPF socket policy operation to send unintended, uninitialized bytes. This may expose residual data and cause receiving applications to reject malformed TLS records. Exposure depends on whether the affected kTLS and BPF features are used together.

Executive priority

Treat as a high-priority, targeted kernel update rather than an indiscriminate emergency. Rapidly identify systems using kTLS with BPF socket policy, patch those first, and follow normal accelerated maintenance for remaining affected kernels. Escalate if sensitive workloads expose the vulnerable path.

Technical view

When bpf_msg_pop_data() shortens plaintext governed by socket policy, kTLS previously retained the original ciphertext-length calculation. Transmission could therefore include uninitialized bytes after a complete TLS Application Data record, creating potential confidentiality loss, limited corruption, and receiver-side parsing failures.

Likely exposure

Likely exposure is limited to Linux systems using kTLS together with BPF socket policy that invokes bpf_msg_pop_data(). The bundle lists multiple affected kernel branches, but does not provide reliable distribution-specific package ranges. Systems not using this feature combination are unlikely to reach the vulnerable path.

Exploitation context

The supplied record has a CVSS 3.1 score of 8.6 and a network attack vector, but it is not listed in KEV. No supplied source reports active exploitation or a public exploit. Practical reachability and attacker control over the relevant BPF policy path remain unclear from the evidence.

Researcher notes

The defect is a stale length calculation after plaintext reduction, not a conventional TLS cryptographic break. Uninitialized trailing bytes create an information-disclosure concern and can disrupt TLS parsing. The bundle supplies multiple stable-branch fixes but insufficient information to establish exploitability, attacker prerequisites, or precise distribution package boundaries.

Mitigation direction

  • Update to a vendor-supported kernel containing the applicable upstream stable fix.
  • Check the Linux distribution's advisory for exact fixed package versions and reboot requirements.
  • Prioritize systems confirmed to use both kTLS and relevant BPF socket policies.
  • If updates are delayed, seek vendor guidance for safely avoiding the affected feature combination.

Validation and detection

  • Inventory running kernel and distribution package versions across Linux systems.
  • Determine whether kTLS and BPF socket policies using bpf_msg_pop_data() are deployed.
  • Compare installed kernels with vendor advisories or the applicable upstream stable fix.
  • Confirm updated systems booted into the fixed kernel.
  • Review TLS receiver logs for unexplained record-parsing failures or malformed trailing data.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-38608 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.6 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
12Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.6CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L3.94.7Linux

Vulnerability scoring details

Base CVSS 3.1 score

8.6High
CVSS 3.1 vector shape for CVE-2025-38608Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28, 7246d8ed4dcce23f7509949a77be15fa9f0e3d28unaffected
LinuxLinux5.0, 0, 5.4.297, 5.10.241, 5.15.190, 6.1.148, 6.6.102, 6.12.42, 6.15.10, 6.16.1, 6.17affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.