PT-2025-38558 · Linux+4 · Linux Kernel+4

Published

2025-09-01

·

Updated

2026-05-26

·

CVE-2025-39851

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability exists in the Linux kernel related to VXLAN FDB entries. Specifically, when learning is enabled, an incoming packet attempting to refresh an FDB entry pointing to an FDB nexthop group (which lacks a remote) could cause a NULL pointer dereference (NPD). This occurs because packets are not dropped early enough in the process, leading to dereferencing a non-existent remote. The issue was identified during EVPN deployments where learning is disabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-67536
AZL-72343
BDU:2025-13878
CVE-2025-39851
DSA-6008-1
ECHO-3E72-2DEB-600B
OESA-2025-2465
OESA-2025-2466
OESA-2025-2467
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu