CVE-2025-38639: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nfacct: don't assume acct name is null-terminated BUG: KASAN: slab-out-of-bounds in .. lib/vsprintf.c:721 Read of size 1 at addr ffff88801eac95c8 by task syz-executor183/5851 [..] string+0x231/0x2b0 lib/vsprintf.c:721 vsnprintf+0x739/0xf00 lib/vsprintf.c:2874 [..] nfacct_mt_checkentry+0xd2/0xe0 net/netfilter/xt_nfacct.c:41 xt_check_match+0x3d1/0xab0 net/netfilter/x_tables.c:523 nfnl_acct_find_get() handles non-null input, but the error printk relied on its presence.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 3.3, before 5.4.297 (fixed in 5.4.297); from 5.5, before 5.10.241 (fixed in 5.10.241); from 5.11, before 5.15.190 (fixed in 5.15.190); from 5.16, before 6.1.148 (fixed in 6.1.148); from 6.2, before 6.6.102 (fixed in 6.6.102); from 6.7, before 6.12.42 (fixed in 6.12.42); …

Published 2025-08-22. Last modified 2026-07-30.