Junglewise Threat Intelligence

CVE-2025-38683: Linux Kernel hv_netvsc NULL pointer dereference in namespace deletion

CVE-2025-38683 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Hyper-V network driver can cause a system crash (kernel panic) when a network namespace is deleted. This occurs because the system incorrectly handles virtual network interfaces during the cleanup process, leading to a memory error. An attacker with local access could potentially exploit this to cause a denial-of-service, disrupting operations and system availability.

Technical details

A NULL pointer dereference exists in the Linux kernel's hv_netvsc driver within the network namespace cleanup path. When a network namespace is deleted, the 'default_device_exit_batch' and 'default_device_exit_net' functions are called. If a Virtual Function (VF) NIC is automatically moved back to the default namespace during this process, it can cause the 'for_each_netdev_safe' loop to fail to detect the end of the list, resulting in a NULL pointer dereference and kernel panic. The fix involves moving the namespace change logic to a workqueue and properly utilizing 'rtnl_lock' to prevent concurrent modifications to the netdev list during cleanup. Patches have been released for various stable kernel branches.

Affected products

  • Linux Linux Kernel 4.19.323 to 4.20, 5.4.285 to 5.5, 5.10.229 to 5.10.241, 5.15.170 to 5.15.190, 6.1.115 to 6.1.149, 6.6.59 to 6.6.103, 6.11.6 to 6.12, 6.12.1 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-08-06: other: Patch authored
  • 2025-09-04: disclosed: CVE published

References

Related threats