CVE-2025-23259

NameCVE-2025-23259
DescriptionNVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information disclosure and denial of service on the network interface.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dpdk (PTS)bullseye20.11.10-1~deb11u1vulnerable
bullseye (security)20.11.6-1~deb11u1vulnerable
bookworm22.11.9-1~deb12u1vulnerable
bookworm (security)22.11.7-1~deb12u1vulnerable
trixie24.11.3-1~deb13u1fixed
forky, sid24.11.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dpdksourcetrixie24.11.3-1~deb13u1
dpdksource(unstable)24.11.3-1

Notes

[bookworm] - dpdk <no-dsa> (Minor issue)
[bullseye] - dpdk <postponed> (Minor issue)
https://nvidia.custhelp.com/app/answers/detail/a_id/5655

Search for package or bug name: Reporting problems