CVE-2025-38570
HIGHLinux Kernel 6.14-6.15.9, 6.16.0 - Use-After-Free in fbnic NAPI Queue Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: unlink NAPIs from queues on error to open CI hit a UaF in fbnic in the AF_XDP portion of the queues.py test. The UaF is in the __sk_mark_napi_id_once() call in xsk_bind(), NAPI has been freed. Looks like the device failed to open earlier, and we lack clearing the NAPI pointer from the queue.
References (3)
Core 3
Scores
CVSS v3
7.8
EPSS
0.0015
EPSS Percentile
4.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (11)
linux/Kernel
6.14.0 - 6.15.10linux
linux/Kernel
6.16.0 - 6.16.1linux
Linux/Linux
< 6.14
Linux/Linux
557d02238e05eb66b9aba9a1f90f3a2131c6c887 - 21d3f8441c7f317b93ba6a8029610c8b7e3773db
Linux/Linux
557d02238e05eb66b9aba9a1f90f3a2131c6c887 - 4b31bcb025cb497da2b01f87173108ff32d350d2
Linux/Linux
557d02238e05eb66b9aba9a1f90f3a2131c6c887 - 4b59f9deff3bdb52b223c85048f1d2924803b817
Linux/Linux
6.14
Linux/Linux
6.15.10 - 6.15.*
Linux/Linux
6.16.1 - 6.16.*
Linux/Linux
6.17
... and 1 more
Published
Aug 19, 2025
Tracked Since
Feb 18, 2026