imPC@ndo EN

Tracker / CVE-2025-37820

CVE-2025-37820

Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: xen-netfront: handle NULL returned by xdp_convert_buff_to_frame() The function xdp_convert_buff_to_frame() may return NULL if it fails to correctly convert the XDP buffer into an XDP frame due to memory constraints, internal errors, or invalid data. Failing to check for NULL may lead to a NULL pointer dereference if the result is used later in processing, potentially causing crashes, data corruption, or undefined behavior. On XDP redirect failure, the associated page must be released explicitly if it was previously retained via get_page(). Failing to do so may result in a memory leak, as the pages reference count is not decremented.

Prodotti e versioni affette

debian debian_linux
linux linux_kernel
linux linux_kernel · 5.9 → 6.1.136
linux linux_kernel · 6.13 → 6.14.5
linux linux_kernel · 6.2 → 6.6.89
linux linux_kernel · 6.7 → 6.12.26

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti