PT-2025-27708 · Linux+6 · Linux Kernel+6
Published
2025-06-02
·
Updated
2026-04-20
·
CVE-2025-38122
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A potential NULL pointer dereference issue has been identified in the Linux kernel, specifically in the
gve alloc pending packet() function within the TX DQO. This function can return NULL, but the returned pointer was not checked for NULL before being dereferenced in gve tx add skb dqo(). To address this, a missing NULL check has been added to prevent potential crashes when memory allocation fails, improving the kernel's robustness in low-memory scenarios.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu