In the Linux kernel, the following vulnerability has been resolved:
atm: clip: prevent NULL deref in clip_push()
Blamed commit missed that vccdestroysocket() calls clip_push() with a NULL skb.
If clipdevs is NULL, clippush() then crashes when reading skb->truesize.
[
{
"signature_version": "v1",
"id": "CVE-2025-38251-0144ef30",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9199e8cb75f13a1650adcb3c6cad42789c43884e",
"digest": {
"function_hash": "157100021036952516268913831921915395494",
"length": 1237.0
},
"target": {
"function": "clip_push",
"file": "net/atm/clip.c"
},
"deprecated": false,
"signature_type": "Function"
},
{
"signature_version": "v1",
"id": "CVE-2025-38251-09bff12e",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a07005a77b18ae59b8471e7e4d991fa9f642b3c2",
"digest": {
"function_hash": "157100021036952516268913831921915395494",
"length": 1237.0
},
"target": {
"function": "clip_push",
"file": "net/atm/clip.c"
},
"deprecated": false,
"signature_type": "Function"
},
{
"signature_version": "v1",
"id": "CVE-2025-38251-583bc7ff",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9199e8cb75f13a1650adcb3c6cad42789c43884e",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109474042589695436140564244214442106880",
"320710356067025963367182251919536486568",
"231012536550281226944443542416345557950",
"4783186141845659314383874440794935825",
"327179399547239526844097069820142914313",
"20524878646672746579337721616403209654",
"67879842150842065445872379802324668137",
"99174705399045550455788537463591486332",
"286394060760763763966950415627795208314",
"230495930481828947443971154259355737082",
"69183238460880385210015765191443036154",
"93995969538592892783582471020485477379"
]
},
"target": {
"file": "net/atm/clip.c"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"id": "CVE-2025-38251-80577b0d",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a07005a77b18ae59b8471e7e4d991fa9f642b3c2",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109474042589695436140564244214442106880",
"320710356067025963367182251919536486568",
"231012536550281226944443542416345557950",
"4783186141845659314383874440794935825",
"327179399547239526844097069820142914313",
"20524878646672746579337721616403209654",
"67879842150842065445872379802324668137",
"99174705399045550455788537463591486332",
"286394060760763763966950415627795208314",
"230495930481828947443971154259355737082",
"69183238460880385210015765191443036154",
"93995969538592892783582471020485477379"
]
},
"target": {
"file": "net/atm/clip.c"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"id": "CVE-2025-38251-c464610b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3c709dce16999bf6a1d2ce377deb5dd6fdd8cb08",
"digest": {
"function_hash": "157100021036952516268913831921915395494",
"length": 1237.0
},
"target": {
"function": "clip_push",
"file": "net/atm/clip.c"
},
"deprecated": false,
"signature_type": "Function"
},
{
"signature_version": "v1",
"id": "CVE-2025-38251-d2b9744f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3c709dce16999bf6a1d2ce377deb5dd6fdd8cb08",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109474042589695436140564244214442106880",
"320710356067025963367182251919536486568",
"231012536550281226944443542416345557950",
"4783186141845659314383874440794935825",
"327179399547239526844097069820142914313",
"20524878646672746579337721616403209654",
"67879842150842065445872379802324668137",
"99174705399045550455788537463591486332",
"286394060760763763966950415627795208314",
"230495930481828947443971154259355737082",
"69183238460880385210015765191443036154",
"93995969538592892783582471020485477379"
]
},
"target": {
"file": "net/atm/clip.c"
},
"deprecated": false,
"signature_type": "Line"
}
]