CVE-2025-38124

MEDIUMNVD 5.55.5
EchelonGraph scoreMEDIUM confidence

Score 5.5 from GitHub Security Advisory published 2025-07-03. NVD baseline CVSS 5.5; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
5.5EG
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 5.5Exploit: None knownExposed: 0

A fix is available — apply it.

In the Linux kernel, the following vulnerability has been resolved:

net: fix udp gso skb_segment after pull from frag_list

Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from frag_list") detected invalid geometry in frag_list skbs and redirects them from skb_segment_list to more robust skb_segment. But some packets with modified geometry can also hit bugs in that code. We don't know how many such cases exist. Addressing each one by one also requires touching the complex skb_segment code, which risks introducing bugs for other types of skbs. Instead, linearize all these packets that fail the basic invariants on gso fraglist skbs. That is more robust.

If only part of the fraglist payload is pulled into head_skb, it will always cause exception when splitting skbs by skb_segment. For detailed call stack information, see below.

Valid SKB_GSO_FRAGLIST skbs

  • consist of two or more segments
  • the head_skb holds the protocol headers plus first gso_size
  • one or more frag_list skbs hold exactly one segment
  • all but the last must be gso_size

Optional datapath hooks such as NAT and BPF (bpf_skb_pull_data) can modify fraglist skbs, breaking these invariants.

In extreme cases they pull one part of data into skb linear. For UDP, this causes three payloads with lengths of (11,11,10) bytes were pulled tail to become (12,10,10) bytes.

The skbs no longer meets the above SKB_GSO_FRAGLIST conditions because payload was pulled into head_skb, it needs to be linearized before pass to regular skb_segment.

skb_segment+0xcd0/0xd14 __udp_gso_segment+0x334/0x5f4 udp4_ufo_fragment+0x118/0x15c inet_gso_segment+0x164/0x338 skb_mac_gso_segment+0xc4/0x13c __skb_gso_segment+0xc4/0x124 validate_xmit_skb+0x9c/0x2c0 validate_xmit_skb_list+0x4c/0x80 sch_direct_xmit+0x70/0x404 __dev_queue_xmit+0x64c/0xe5c neigh_resolve_output+0x178/0x1c4 ip_finish_output2+0x37c/0x47c __ip_finish_output+0x194/0x240 ip_finish_output+0x20/0xf4 ip_output+0x100/0x1a0 NF_HOOK+0xc4/0x16c ip_forward+0x314/0x32c ip_rcv+0x90/0x118 __netif_receive_skb+0x74/0x124 process_backlog+0xe8/0x1a4 __napi_poll+0x5c/0x1f8 net_rx_action+0x154/0x314 handle_softirqs+0x154/0x4b8

[118.376811] [C201134] rxq0_pus: [name:bug&]kernel BUG at net/core/skbuff.c:4278! [118.376829] [C201134] rxq0_pus: [name:traps&]Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP [118.470774] [C201134] rxq0_pus: [name:mrdump&]Kernel Offset: 0x178cc00000 from 0xffffffc008000000 [118.470810] [C201134] rxq0_pus: [name:mrdump&]PHYS_OFFSET: 0x40000000 [118.470827] [C201134] rxq0_pus: [name:mrdump&]pstate: 60400005 (nZCv daif +PAN -UAO) [118.470848] [C201134] rxq0_pus: [name:mrdump&]pc : [0xffffffd79598aefc] skb_segment+0xcd0/0xd14 [118.470900] [C201134] rxq0_pus: [name:mrdump&]lr : [0xffffffd79598a5e8] skb_segment+0x3bc/0xd14 [118.470928] [C201134] rxq0_pus: [name:mrdump&]sp : ffffffc008013770

CVSS v3
5.5
EG Score
5.5(medium)
EG Risk
29(Track)
EG Risk 29/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity55% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
34%
KEV
Not listed

Published

July 3, 2025

Last Modified

August 5, 2026

Advisory Details (7)

Auto-updated Aug 2, 2026
⚠️ Active exploitation confirmed. Patch available.
generic Patch Available

[SECURITY] [DLA 4328-1] linux-6.1 security update

https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
generic

net: fix udp gso skb_segment after pull from frag_list - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/a04302867094bdc6efac1b598370fc47cf3f2388
generic

net: fix udp gso skb_segment after pull from frag_list - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/85eef1748c024da1a191aed56b30a3a65958c50c
generic

net: fix udp gso skb_segment after pull from frag_list - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4399f59a9467a324ed46657555f0e1f209a14acb
generic

net: fix udp gso skb_segment after pull from frag_list - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/3382a1ed7f778db841063f5d7e317ac55f9e7f72
generic

net: fix udp gso skb_segment after pull from frag_list - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/0e65f38bd1aa14ea86e221b7bb814d38278d86c3

Vendor Advisories for CVE-2025-38124(2)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Patch Availability(26)

Vendor / EcosystemFixed in / PatchReleasedSource
ubuntulinux-tools-realtime-hwe-24.04-edge (6.14.0-1012.12~24.04.1) @ noble2026-05-21ubuntu
ubuntulinux-tools-azure-6.14 (6.14.0-1012.12) @ plucky2026-05-21ubuntu
ubuntulinux-tools-raspi-6.14 (6.14.0-1014.14) @ plucky2026-05-21ubuntu
ubuntulinux-virtual-6.8 (6.8.0-100.100) @ noble2026-05-21ubuntu
ubuntulinux-virtual-hwe-24.04-edge (6.14.0-32.32~24.04.1) @ noble2026-05-21ubuntu
ubuntulinux-virtual-hwe-24.04-edge (6.14.0-32.32) @ plucky2026-05-21ubuntu
ubuntulinux-tools-oem-6.14 (6.14.0-1012.12) @ noble2026-05-21ubuntu
ubuntulinux-tools-oracle-edge (6.14.0-1013.13~24.04.1) @ noble2026-05-21ubuntu
ubuntulinux-virtual-hwe-22.04-edge (6.8.0-100.100~22.04.1) @ jammy2026-05-21ubuntu
ubuntulinux-tools-lowlatency-hwe-20.04-edge (6.8.0-100.100.1) @ noble2026-05-21ubuntu
ubuntulinux-tools-ibm-lts-24.04 (6.8.0-1044.44) @ noble2026-05-21ubuntu
ubuntulinux-tools-gcp-fips-6.8 (6.8.0-1047.50+fips1) @ noble2026-05-21ubuntu
ubuntulinux-tools-azure-lts-24.04 (6.8.0-1046.52) @ noble2026-05-21ubuntu
ubuntulinux-tools-realtime-6.8.1 (6.8.1-1041.42) @ noble2026-05-21ubuntu
ubuntulinux-tools-gcp-edge (6.8.0-1047.50~22.04.2) @ jammy2026-05-21ubuntu
ubuntulinux-tools-oracle-lts-24.04 (6.8.0-1043.44) @ noble2026-05-21ubuntu
ubuntulinux-tools-fips-6.8 (6.8.0-100.100+fips1) @ noble2026-05-21ubuntu
ubuntulinux-tools-realtime-hwe-22.04 (6.8.1-1041.42~22.04.1) @ jammy2026-05-21ubuntu
ubuntulinux-tools-gke-64k-6.8 (6.8.0-1043.48) @ noble2026-05-21ubuntu
ubuntulinux-tools-nvidia-lowlatency-64k-6.8 (6.8.0-1046.49.1) @ noble2026-05-21ubuntu
ubuntulinux-xilinx-zynqmp (6.8.0.1023.24) @ noble2026-05-21ubuntu
ubuntulinux-tools-azure-edge (6.8.0-1051.57~22.04.1) @ jammy2026-05-21ubuntu
ubuntulinux-tools-azure-fips-6.8 (6.8.0-1046.52+fips1) @ noble2026-05-21ubuntu
redhatkernel-0:6.12.0-55.28.1.el10_02025-08-18redhat
redhatkernel-0:5.14.0-570.35.1.el9_62025-08-18redhat
linuxKernel @ 6.1.142osv

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Affected Packages

(4 across 4 ecosystems)
Debian:11(1)
PackageVulnerable rangeFixed inDependents
linux-6.16.1.106-3~deb11u1 ... 6.1.148-1~deb11u1 (11 versions)6.1.153-1~deb11u1
Debian:12(1)
PackageVulnerable rangeFixed inDependents
linux6.1.106-1 ... 6.1.99-1 (41 versions)6.1.147-1
Debian:13(1)
PackageVulnerable rangeFixed inDependents
linux6.12.35-1
Debian:14(1)
PackageVulnerable rangeFixed inDependents
linux6.12.35-1

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Additional Vendor Advisories

(23)

Data Freshness Timeline

(refreshed 5× in last 7d / 27× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

Showing the most recent 100 of 169 total refreshes for this CVE.

  1. 2026-09-18 19:27 UTCEPSS rescore
  2. 2026-09-17 19:29 UTCEPSS rescore
  3. 2026-09-16 14:07 UTCEPSS rescore
  4. 2026-09-16 05:14 UTCEPSS rescore
  5. 2026-09-13 16:46 UTCEPSS rescore
  6. 2026-09-12 15:00 UTCEPSS rescore
  7. 2026-09-11 14:52 UTCEPSS rescore
  8. 2026-09-11 09:35 UTCEPSS rescore
  9. 2026-09-10 09:33 UTCEPSS rescore
  10. 2026-09-08 21:59 UTCEPSS rescore
  11. 2026-09-07 16:00 UTCEPSS rescore
  12. 2026-09-07 11:48 UTCOSV refresh
  13. 2026-09-06 13:46 UTCEPSS rescore
  14. 2026-09-04 05:05 UTCEPSS rescore
  15. 2026-09-02 14:11 UTCEPSS rescore
  16. 2026-09-01 13:53 UTCEPSS rescore
  17. 2026-09-01 04:38 UTCEPSS rescore
  18. 2026-08-30 19:16 UTCEPSS rescore
  19. 2026-08-30 01:21 UTCEPSS rescore
  20. 2026-08-28 21:40 UTCEPSS rescore
  21. 2026-08-27 14:24 UTCEPSS rescore
  22. 2026-08-26 14:45 UTCEPSS rescore
  23. 2026-08-25 13:48 UTCEPSS rescore
  24. 2026-08-23 00:18 UTCEPSS rescore
  25. 2026-08-21 23:48 UTCEPSS rescore
Show 75 more
  1. 2026-08-20 22:54 UTCEPSS rescore
  2. 2026-08-20 21:01 UTCOSV refresh
  3. 2026-08-19 17:03 UTCEPSS rescore
  4. 2026-08-19 17:03 UTCEPSS rescore
  5. 2026-08-18 13:47 UTCEPSS rescore
  6. 2026-08-17 13:46 UTCEPSS rescore
  7. 2026-08-16 14:55 UTCEPSS rescore
  8. 2026-08-16 02:13 UTCEPSS rescore
  9. 2026-08-15 01:29 UTCEPSS rescore
  10. 2026-08-13 21:59 UTCEPSS rescore
  11. 2026-08-12 13:50 UTCEPSS rescore
  12. 2026-08-09 13:46 UTCEPSS rescore
  13. 2026-08-08 16:36 UTCEPSS rescore
  14. 2026-08-07 16:26 UTCEPSS rescore
  15. 2026-08-06 13:46 UTCEPSS rescore
  16. 2026-08-05 13:06 UTCEG score recompute
  17. 2026-08-05 13:06 UTCVendor advisory
  18. 2026-08-05 13:06 UTCGHSA enrichment
  19. 2026-08-04 15:09 UTCEPSS rescore
  20. 2026-08-04 10:37 UTCEPSS rescore
  21. 2026-08-03 10:35 UTCEPSS rescore
  22. 2026-08-02 02:26 UTCEPSS rescore
  23. 2026-08-01 04:15 UTCEPSS rescore
  24. 2026-07-30 16:27 UTCEPSS rescore
  25. 2026-07-30 07:08 UTCEG score recompute
  26. 2026-07-30 07:08 UTCVendor advisory
  27. 2026-07-30 07:08 UTCGHSA enrichment
  28. 2026-07-30 06:24 UTCNVD updateCVSS v3 → 5.5 · severity → MEDIUM
  29. 2026-07-30 01:29 UTCEPSS rescore
  30. 2026-07-28 15:35 UTCEPSS rescore
  31. 2026-07-27 17:27 UTCOSV refresh
  32. 2026-07-25 14:17 UTCEPSS rescore
  33. 2026-07-25 14:17 UTCEPSS rescore
  34. 2026-07-24 14:17 UTCEPSS rescore
  35. 2026-07-23 02:54 UTCEG score recompute
  36. 2026-07-22 14:07 UTCEPSS rescore
  37. 2026-07-22 14:07 UTCEPSS rescore
  38. 2026-07-21 15:24 UTCEPSS rescore
  39. 2026-07-20 17:07 UTCEPSS rescore
  40. 2026-07-19 14:30 UTCEPSS rescore
  41. 2026-07-19 14:30 UTCEPSS rescore
  42. 2026-07-16 17:02 UTCEPSS rescore
  43. 2026-07-15 16:57 UTCEPSS rescore
  44. 2026-07-15 16:57 UTCEPSS rescore
  45. 2026-07-15 01:59 UTCEPSS rescore
  46. 2026-07-15 01:59 UTCEPSS rescore
  47. 2026-07-14 13:11 UTCMITRE cvelistV5
  48. 2026-07-13 22:29 UTCEPSS rescore
  49. 2026-07-13 22:29 UTCEPSS rescore
  50. 2026-07-13 06:12 UTCEPSS rescore
  51. 2026-07-12 05:46 UTCEPSS rescore
  52. 2026-07-11 08:27 UTCEPSS rescore
  53. 2026-07-11 08:27 UTCEPSS rescore
  54. 2026-07-10 10:22 UTCOSV refresh
  55. 2026-07-09 19:09 UTCEPSS rescore
  56. 2026-07-09 19:09 UTCEPSS rescore
  57. 2026-07-07 13:45 UTCEPSS rescore
  58. 2026-07-06 02:23 UTCEPSS rescore
  59. 2026-07-05 02:30 UTCEPSS rescore
  60. 2026-07-04 06:30 UTCEPSS rescore
  61. 2026-07-01 15:06 UTCEPSS rescore
  62. 2026-07-01 15:06 UTCEPSS rescore
  63. 2026-06-30 23:22 UTCEPSS rescore
  64. 2026-06-30 23:22 UTCEPSS rescore
  65. 2026-06-29 14:06 UTCEPSS rescore
  66. 2026-06-29 14:06 UTCEPSS rescore
  67. 2026-06-28 14:07 UTCEPSS rescore
  68. 2026-06-28 14:07 UTCEPSS rescore
  69. 2026-06-28 04:55 UTCEPSS rescore
  70. 2026-06-28 04:55 UTCEPSS rescore
  71. 2026-06-27 03:08 UTCEPSS rescore
  72. 2026-06-27 03:08 UTCEPSS rescore
  73. 2026-06-25 13:49 UTCEPSS rescore
  74. 2026-06-25 13:49 UTCEPSS rescore
  75. 2026-06-24 14:04 UTCEPSS rescore

Frequently asked(5)

What is CVE-2025-38124?
CVE-2025-38124 is a medium vulnerability published on July 3, 2025. In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skbsegment after pull from fraglist Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from fraglist") detected invalid geometry in fraglist skbs and redirects them from skbsegmentlist to…
When was CVE-2025-38124 disclosed?
CVE-2025-38124 was first published in the National Vulnerability Database on July 3, 2025, with the most recent update on August 5, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2025-38124 actively exploited?
CVE-2025-38124 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 65.6% of all scored CVEs.
What is the CVSS score of CVE-2025-38124?
CVE-2025-38124 has a CVSS v3 base score of 5.5 (NVD).
How do I remediate CVE-2025-38124?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2025-38124, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-38124

Explore →

Is Your Infrastructure Affected by CVE-2025-38124?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.