{"id":"DEBIAN-CVE-2025-39758","details":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages  Ever since commit c2ff29e99a76 (\"siw: Inline do_tcp_sendpages()\"), we have been doing this:  static int siw_tcp_sendpages(struct socket *s, struct page **page, int offset,                              size_t size) [...]         /* Calculate the number of bytes we need to push, for this page          * specifically */         size_t bytes = min_t(size_t, PAGE_SIZE - offset, size);         /* If we can't splice it, then copy it in, as normal */         if (!sendpage_ok(page[i]))                 msg.msg_flags &= ~MSG_SPLICE_PAGES;         /* Set the bvec pointing to the page, with len $bytes */         bvec_set_page(&bvec, page[i], bytes, offset);         /* Set the iter to $size, aka the size of the whole sendpages (!!!) */         iov_iter_bvec(&msg.msg_iter, ITER_SOURCE, &bvec, 1, size); try_page_again:         lock_sock(sk);         /* Sendmsg with $size size (!!!) */         rv = tcp_sendmsg_locked(sk, &msg, size);  This means we've been sending oversized iov_iters and tcp_sendmsg calls for a while. This has a been a benign bug because sendpage_ok() always returned true. With the recent slab allocator changes being slowly introduced into next (that disallow sendpage on large kmalloc allocations), we have recently hit out-of-bounds crashes, due to slight differences in iov_iter behavior between the MSG_SPLICE_PAGES and \"regular\" copy paths:  (MSG_SPLICE_PAGES) skb_splice_from_iter   iov_iter_extract_pages     iov_iter_extract_bvec_pages       uses i-\u003enr_segs to correctly stop in its tracks before OoB'ing everywhere   skb_splice_from_iter gets a \"short\" read  (!MSG_SPLICE_PAGES) skb_copy_to_page_nocache copy=iov_iter_count  [...]    copy_from_iter         /* this doesn't help */         if (unlikely(iter-\u003ecount \u003c len))                 len = iter-\u003ecount;           iterate_bvec             ... and we run off the bvecs  Fix this by properly setting the iov_iter's byte count, plus sending the correct byte count to tcp_sendmsg_locked.","modified":"2026-08-27T23:05:31.632091392Z","published":"2025-09-11T17:15:39.663Z","upstream":["CVE-2025-39758"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-39758"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.43-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-39758.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.16.3-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.3-1~bpo13+1","6.16~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-39758.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}