CVE-2025-38251

In the Linux kernel, the following vulnerability has been resolved: atm: clip: prevent NULL deref in clip_push() Blamed commit missed that vcc_destroy_socket() calls clip_push() with a NULL skb. If clip_devs is NULL, clip_push() then crashes when reading skb->truesize.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jul 2025, 17:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/41f6420ee845006354c004839fed07da71e34aee -

10 Jul 2025, 15:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/9199e8cb75f13a1650adcb3c6cad42789c43884e -

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: atm: clip: previene la deref NULL en clip_push(). El commit responsable no detectó que vcc_destroy_socket() llama a clip_push() con un skb NULL. Si clip_devs es NULL, clip_push() se bloquea al leer skb->truesize.

09 Jul 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 11:15

Updated : 2025-07-17 17:15


NVD link : CVE-2025-38251

Mitre link : CVE-2025-38251

CVE.ORG link : CVE-2025-38251


JSON object : View

Products Affected

No product.

CWE

No CWE.