In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix oops due to non-existence of prealloc backlog struct
If an AFRXRPC service socket is opened and bound, but calls are preallocated, then rxrpcallocincomingcall() will oops because the rxrpc_backlog struct doesn't get allocated until the first preallocation is made.
Fix this by returning NULL from rxrpcallocincoming_call() if there is no backlog struct. This will cause the incoming call to be aborted.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38514.json"
}[
{
"signature_version": "v1",
"digest": {
"length": 2123.0,
"function_hash": "212527817771460121810552651529846416611"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-38514-13d090b1",
"target": {
"function": "rxrpc_alloc_incoming_call",
"file": "net/rxrpc/call_accept.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@efc1b2b7c1a308b60df8f36bc2d7ce16d3999364"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"295049098256509518296957906318580387410",
"74643106715526304910735915445097596448",
"188639669997653022634866737942311501108"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38514-645d3e11",
"target": {
"file": "net/rxrpc/call_accept.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@efc1b2b7c1a308b60df8f36bc2d7ce16d3999364"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"295049098256509518296957906318580387410",
"74643106715526304910735915445097596448",
"188639669997653022634866737942311501108"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38514-a3f4ae32",
"target": {
"file": "net/rxrpc/call_accept.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2c2e9ebeb036f9b1b09325ec5cfdfe0e78f357c3"
},
{
"digest": {
"length": 2123.0,
"function_hash": "212527817771460121810552651529846416611"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-38514-be5b481f",
"target": {
"function": "rxrpc_alloc_incoming_call",
"file": "net/rxrpc/call_accept.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2c2e9ebeb036f9b1b09325ec5cfdfe0e78f357c3"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38514.json"