In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_nfacct: don't assume acct name is null-terminated
BUG: KASAN: slab-out-of-bounds in .. lib/vsprintf.c:721 Read of size 1 at addr ffff88801eac95c8 by task syz-executor183/5851 [..] string+0x231/0x2b0 lib/vsprintf.c:721 vsnprintf+0x739/0xf00 lib/vsprintf.c:2874 [..] nfacctmtcheckentry+0xd2/0xe0 net/netfilter/xtnfacct.c:41 xtcheckmatch+0x3d1/0xab0 net/netfilter/xtables.c:523
nfnlacctfind_get() handles non-null input, but the error printk relied on its presence.
[
{
"digest": {
"line_hashes": [
"77439759465556084366898467408293090927",
"188569522014125721316321734316826638776",
"236185150672768903097211589778524834739",
"113042194517016520477431879346091464666",
"69743170407547305933242761675879692716"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e18939176e657a3a20bfbed357b8c55a9f82aba3",
"target": {
"file": "net/netfilter/xt_nfacct.c"
},
"id": "CVE-2025-38639-1c8c88f6",
"signature_type": "Line"
},
{
"digest": {
"length": 289.0,
"function_hash": "68107490386865819451506465595247169147"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e021a1eee196887536a6630c5492c23a4c78d452",
"target": {
"function": "nfacct_mt_checkentry",
"file": "net/netfilter/xt_nfacct.c"
},
"id": "CVE-2025-38639-25e5d910",
"signature_type": "Function"
},
{
"digest": {
"length": 289.0,
"function_hash": "68107490386865819451506465595247169147"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@df13c9c6ce1d55c31d1bd49db65a7fbbd86aab13",
"target": {
"function": "nfacct_mt_checkentry",
"file": "net/netfilter/xt_nfacct.c"
},
"id": "CVE-2025-38639-4233c67c",
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"77439759465556084366898467408293090927",
"188569522014125721316321734316826638776",
"236185150672768903097211589778524834739",
"113042194517016520477431879346091464666",
"69743170407547305933242761675879692716"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e021a1eee196887536a6630c5492c23a4c78d452",
"target": {
"file": "net/netfilter/xt_nfacct.c"
},
"id": "CVE-2025-38639-7f447abd",
"signature_type": "Line"
},
{
"digest": {
"line_hashes": [
"77439759465556084366898467408293090927",
"188569522014125721316321734316826638776",
"236185150672768903097211589778524834739",
"113042194517016520477431879346091464666",
"69743170407547305933242761675879692716"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@df13c9c6ce1d55c31d1bd49db65a7fbbd86aab13",
"target": {
"file": "net/netfilter/xt_nfacct.c"
},
"id": "CVE-2025-38639-f086c282",
"signature_type": "Line"
},
{
"digest": {
"length": 289.0,
"function_hash": "68107490386865819451506465595247169147"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e18939176e657a3a20bfbed357b8c55a9f82aba3",
"target": {
"function": "nfacct_mt_checkentry",
"file": "net/netfilter/xt_nfacct.c"
},
"id": "CVE-2025-38639-fdd72a78",
"signature_type": "Function"
}
]