CVE-2025-38432: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: netpoll: Initialize UDP checksum field before checksumming commit f1fce08e63fe ("netpoll: Eliminate redundant assignment") removed the initialization of the UDP checksum, which was wrong and broke netpoll IPv6 transmission due to bad checksumming. udph->check needs to be set before calling csum_ipv6_magic().

Affected products

  • Linux Linux Kernel: from 6.15, before 6.15.5 (fixed in 6.15.5); version 6.16 only

Published 2025-07-25. Last modified 2026-06-17.