CVE-2025-37755

In the Linux kernel, the following vulnerability has been resolved: net: libwx: handle page_pool_dev_alloc_pages error page_pool_dev_alloc_pages could return NULL. There was a WARN_ON(!page) but it would still proceed to use the NULL pointer and then crash. This is similar to commit 001ba0902046 ("net: fec: handle page_pool_dev_alloc_pages error"). This is found by our static analysis tool KNighter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*

History

06 Nov 2025, 21:27

Type Values Removed Values Added
CWE CWE-476
CPE cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/1dd13c60348f515acd8c6f25a561b9c4e3b04fea - () https://git.kernel.org/stable/c/1dd13c60348f515acd8c6f25a561b9c4e3b04fea - Patch
References () https://git.kernel.org/stable/c/7f1ff1b38a7c8b872382b796023419d87d78c47e - () https://git.kernel.org/stable/c/7f1ff1b38a7c8b872382b796023419d87d78c47e - Patch
References () https://git.kernel.org/stable/c/90bec7cef8805f9a23145e070dff28a02bb584eb - () https://git.kernel.org/stable/c/90bec7cef8805f9a23145e070dff28a02bb584eb - Patch
References () https://git.kernel.org/stable/c/ad81d666e114ebf989fc9994d4c93d451dc60056 - () https://git.kernel.org/stable/c/ad81d666e114ebf989fc9994d4c93d451dc60056 - Patch
References () https://git.kernel.org/stable/c/c17ef974bfcf1a50818168b47c4606b425a957c4 - () https://git.kernel.org/stable/c/c17ef974bfcf1a50818168b47c4606b425a957c4 - Patch
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: libwx: error en el controlador page_pool_dev_alloc_pages. page_pool_dev_alloc_pages podría devolver NULL. Se ejecutó un WARN_ON(!page), pero seguía usando el puntero NULL y se bloqueaba. Esto es similar a la confirmación 001ba0902046 ("net: fec: error en el controlador page_pool_dev_alloc_pages"). Esta vulnerabilidad fue detectada por nuestra herramienta de análisis estático Knighter.

01 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 13:15

Updated : 2025-11-06 21:27


NVD link : CVE-2025-37755

Mitre link : CVE-2025-37755

CVE.ORG link : CVE-2025-37755


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference