PT-2025-38557 · Linux+4 · Linux Kernel+4

CVE-2025-39850

·

Publicado

2025-09-01

·

Atualizado

2026-08-30

CVSS v2.0

6.0

Média

VetorAV:L/AC:H/Au:S/C:C/I:C/A:C
Nome do Software Vulnerável e Versões Afetadas Versões do kernel Linux 6.17.0-rc2-virtme-g2a89cb21162c até 6.17.0-rc2-virtmne-g6ee90cb26014
Descrição Um problema de desreferência de ponteiro nulo (NPD) foi identificado no módulo vxlan ao utilizar objetos nexthop com a opção "proxy" habilitada. Isso ocorre porque o código assume incorretamente um destino remoto válido para entradas FDB associadas a grupos nexthop FDB. A exploração pode ser desencadeada por solicitações ARP e mensagens Neighbor Solicitation IPv6, potencialmente levando à instabilidade do sistema.
Recomendações As versões do kernel Linux anteriores a 6.17.0-rc2-virtme-g2a89cb21162c e anteriores a 6.17.0-rc2-virtmne-g6ee90cb26014 devem ser atualizadas.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-67565
AZL-72340
BDU:2025-13882
CVE-2025-39850
DSA-6008-1
ECHO-7AC1-F48B-3F73
OESA-2025-2465
OESA-2025-2466
OESA-2025-2467
OESA-2025-2469
OESA-2025-2470
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
SUSE-SU-2026:20560-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Produtos afetados

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu