CVE-2025-38270

HIGH

Linux Kernel - napi_complete() Use-After-Free in netdevsim

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: drv: netdevsim: don't napi_complete() from netpoll netdevsim supports netpoll. Make sure we don't call napi_complete() from it, since it may not be scheduled. Breno reports hitting a warning in napi_complete_done(): WARNING: CPU: 14 PID: 104 at net/core/dev.c:6592 napi_complete_done+0x2cc/0x560 __napi_poll+0x2d8/0x3a0 handle_softirqs+0x1fe/0x710 This is presumably after netpoll stole the SCHED bit prematurely.

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 5.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (12)
linux/Kernel 6.10.0 - 6.12.34linux
linux/Kernel 6.13.0 - 6.15.3linux
Linux/Linux < 6.10
Linux/Linux 3762ec05a9fbda16aaaa2568df679ab8ad13f38d - 1264971017b4d7141352a7fe29021bdfce5d885d
Linux/Linux 3762ec05a9fbda16aaaa2568df679ab8ad13f38d - 6837dd877270c57689bd866de9f3de14172c2439
Linux/Linux 3762ec05a9fbda16aaaa2568df679ab8ad13f38d - a8ff2e362d901200a1075c3ca9c56d9c7bbef389
Linux/Linux 6.10
Linux/Linux 6.12.34 - 6.12.*
Linux/Linux 6.15.3 - 6.15.*
Linux/Linux 6.16
... and 2 more
Published Jul 10, 2025
Tracked Since Feb 18, 2026