Junglewise Threat Intelligence

CVE-2025-38735: Linux Kernel gve driver NULL pointer dereference during shutdown

CVE-2025-38735 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Google Virtual Ethernet (gve) driver within the Linux kernel can cause a system crash during shutdown. This occurs when certain network management tools attempt to interact with the network interface after the system has already begun tearing down its internal data structures. While typically seen during forced shutdowns of virtual machines, it can lead to a kernel panic, resulting in a complete loss of system availability.

Technical details

A race condition exists in the Google Virtual Ethernet (gve) driver where the shutdown() function tears down internal data structures but does not immediately detach the netdev. Because the device remains visible to userspace and kernel helpers, an ethtool operation dispatched after shutdown() can result in a NULL pointer dereference or use-after-free, leading to a kernel panic. This is particularly observable during forced shutdowns (e.g., on GCP VMs) where userspace may not be fully quiesced. The fix involves calling netif_device_detach() within the shutdown path to ensure the ethtool ioctl handler skips further operations. Patches are available for multiple stable kernel branches including 6.1.149, 6.6.103, 6.12.44, and 6.16.4.

Affected products

  • Linux Linux Kernel 5.17 to 6.16.4
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-08-18: patched: Initial patch submitted by Google engineers
  • 2025-09-05: disclosed: CVE published

References

Related threats