CVE-2025-38006 | Linux Kernel up to 6.6.91/6.12.29/6.14.7 net mctp_dump_addrinfo ifa_index information disclosure (Nessus ID 258130 / WID-SEC-2025-1350)
A vulnerability was found in Linux Kernel up to 6.6.91/6.12.29/6.14.7. It has been classified as problematic. The affected element is the function mctp_dump_addrinfo of the component net. This manipulation of the argument ifa_index causes information disclosure.
This vulnerability is registered as CVE-2025-38006. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.