SB2025090488 - NULL pointer dereference in Linux kernel net hyperv driver
Published: September 4, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-38683)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the netvsc_probe(), netvsc_remove(), netvsc_suspend(), netvsc_event_set_vf_ns() and netvsc_netdev_event() functions in drivers/net/hyperv/netvsc_drv.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2a70cbd1aef8b8be39992ab7b776ce1390091774
- https://git.kernel.org/stable/c/33caa208dba6fa639e8a92fd0c8320b652e5550c
- https://git.kernel.org/stable/c/3467c4ebb334658c6fcf3eabb64a6e8b2135e010
- https://git.kernel.org/stable/c/3ca41ab55d23a0aa71661a5a56a8f06c11db90dc
- https://git.kernel.org/stable/c/4293f6c5ccf735b26afeb6825def14d830e0367b
- https://git.kernel.org/stable/c/4eff1e57a8ef98d70451b94e8437e458b27dd234
- https://git.kernel.org/stable/c/5276896e6923ebe8c68573779d784aaf7d987cce
- https://git.kernel.org/stable/c/d036104947176d030bec64792d54e1b4f4c7f318