PT-2025-16743 · Linux+4 · Linux Kernel+4

Published

2025-03-25

·

Updated

2026-05-26

·

CVE-2025-22103

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference issue has been identified in the Linux kernel, specifically in the l3mdev l3 rcv function. This issue occurs when deleting an l3s ipvlan, which can cause a null pointer dereference. The problem arises because l3mdev l3 rcv() visits dev->l3mdev ops after ipvlan l3s unregister() assigns dev->l3mdev ops to NULL. This can happen due to a race condition between two CPUs. The estimated number of potentially affected devices worldwide is not available.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the NULL pointer dereference in l3mdev l3 rcv. As a temporary workaround, consider avoiding the deletion of l3s ipvlan until a patch is available. However, the exact steps for mitigation are not specified, and the best course of action is to wait for an official patch. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-62501
AZL-69647
BDU:2026-02381
CVE-2025-22103
DSA-6008-1
ECHO-7776-ED3C-BFBE
OESA-2025-1878
OESA-2025-1879
OESA-2025-1880
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
SUSE-SU-2025_02000-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu