CVE-2025-37755

medium

Description

In the Linux kernel, the following vulnerability has been resolved: net: libwx: handle page_pool_dev_alloc_pages error page_pool_dev_alloc_pages could return NULL. There was a WARN_ON(!page) but it would still proceed to use the NULL pointer and then crash. This is similar to commit 001ba0902046 ("net: fec: handle page_pool_dev_alloc_pages error"). This is found by our static analysis tool KNighter.

References

https://git.kernel.org/stable/c/c17ef974bfcf1a50818168b47c4606b425a957c4

https://git.kernel.org/stable/c/ad81d666e114ebf989fc9994d4c93d451dc60056

https://git.kernel.org/stable/c/90bec7cef8805f9a23145e070dff28a02bb584eb

https://git.kernel.org/stable/c/7f1ff1b38a7c8b872382b796023419d87d78c47e

https://git.kernel.org/stable/c/1dd13c60348f515acd8c6f25a561b9c4e3b04fea

Details

Source: Mitre, NVD

Published: 2025-05-01

Updated: 2025-05-02

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00018