Junglewise Threat Intelligence

CVE-2025-39851: Linux Kernel NULL pointer dereference in VXLAN FDB nexthop

CVE-2025-39851 · Severity: high · CVSS 7.5 · Published 2025-09-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's VXLAN networking component could allow an attacker to crash the system. VXLAN is a technology used to create virtual networks over physical infrastructure, often in data centers. By sending specific network traffic, an attacker can trigger a system failure, leading to a complete service outage.

Technical details

A NULL pointer dereference (NPD) exists in the vxlan_snoop() function of the Linux kernel's VXLAN driver. When MAC learning is enabled, an incoming packet may attempt to refresh an FDB entry that points to a nexthop object rather than a remote destination. The code incorrectly attempts to dereference a remote destination pointer that does not exist for nexthop-based entries. This can be triggered remotely by sending packets that target these specific FDB entries, resulting in a kernel panic (DoS). The issue has been resolved by ensuring packets targeting nexthop-based FDB entries are dropped before the invalid dereference occurs.

Affected products

  • Linux Linux Kernel 5.8 to 6.12.46, 6.16.6, 6.17

Timeline

  • 2025-09-01: patched: Initial fix commit authored
  • 2025-09-19: disclosed: CVE published

References

Related threats