Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-37789


In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix nested key length validation in the set() action It's not safe to access nla_len(ovs_key) if the data is smaller than the netlink header. Check that the attribute is OK first.


Published

2025-05-01T14:15:43.290

Last Modified

2025-11-06T17:27:39.670

Status

Analyzed

Source

416baaa9-dc9f-4396-8d5f-8c081fb06d67

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 5.4.293 Yes
Operating System linux linux_kernel < 5.10.237 Yes
Operating System linux linux_kernel < 5.15.181 Yes
Operating System linux linux_kernel < 6.1.135 Yes
Operating System linux linux_kernel < 6.6.88 Yes
Operating System linux linux_kernel < 6.12.25 Yes
Operating System linux linux_kernel < 6.14.4 Yes
Operating System linux linux_kernel 6.15 Yes
Operating System linux linux_kernel 6.15 Yes
Operating System debian debian_linux 11.0 Yes

References