CVE-2025-40236: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hdr_tnl_from_skb() tries to initialize the tunnel metadata but forget to zero unused rxhash fields. This may leak information to another side. Fixing this by zeroing the unused hash fields.
Affected products
- Linux Linux: from 6.17, before 6.17.6 (fixed in 6.17.6)
Published 2025-12-04. Last modified 2026-06-17.