{"id":"DEBIAN-CVE-2025-38146","details":"In the Linux kernel, the following vulnerability has been resolved:  net: openvswitch: Fix the dead loop of MPLS parse  The unexpected MPLS packet may not end with the bottom label stack. When there are many stacks, The label count value has wrapped around. A dead loop occurs, soft lockup/CPU stuck finally.  stack backtrace: UBSAN: array-index-out-of-bounds in /build/linux-0Pa0xK/linux-5.15.0/net/openvswitch/flow.c:662:26 index -1 is out of range for type '__be32 [3]' CPU: 34 PID: 0 Comm: swapper/34 Kdump: loaded Tainted: G           OE   5.15.0-121-generic #131-Ubuntu Hardware name: Dell Inc. PowerEdge C6420/0JP9TF, BIOS 2.12.2 07/14/2021 Call Trace:  \u003cIRQ\u003e  show_stack+0x52/0x5c  dump_stack_lvl+0x4a/0x63  dump_stack+0x10/0x16  ubsan_epilogue+0x9/0x36  __ubsan_handle_out_of_bounds.cold+0x44/0x49  key_extract_l3l4+0x82a/0x840 [openvswitch]  ? kfree_skbmem+0x52/0xa0  key_extract+0x9c/0x2b0 [openvswitch]  ovs_flow_key_extract+0x124/0x350 [openvswitch]  ovs_vport_receive+0x61/0xd0 [openvswitch]  ? kernel_init_free_pages.part.0+0x4a/0x70  ? get_page_from_freelist+0x353/0x540  netdev_port_receive+0xc4/0x180 [openvswitch]  ? netdev_port_receive+0x180/0x180 [openvswitch]  netdev_frame_hook+0x1f/0x40 [openvswitch]  __netif_receive_skb_core.constprop.0+0x23a/0xf00  __netif_receive_skb_list_core+0xfa/0x240  netif_receive_skb_list_internal+0x18e/0x2a0  napi_complete_done+0x7a/0x1c0  bnxt_poll+0x155/0x1c0 [bnxt_en]  __napi_poll+0x30/0x180  net_rx_action+0x126/0x280  ? bnxt_msix+0x67/0x80 [bnxt_en]  handle_softirqs+0xda/0x2d0  irq_exit_rcu+0x96/0xc0  common_interrupt+0x8e/0xa0  \u003c/IRQ\u003e","modified":"2026-09-01T16:06:13.787778608Z","published":"2025-07-03T09:15:29.410Z","upstream":["CVE-2025-38146"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38146"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38146.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38146.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38146.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}