CVE-2025-38683

Source
https://cve.org/CVERecord?id=CVE-2025-38683
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38683.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38683
Downstream
Related
Published
2025-09-04T15:32:38.215Z
Modified
2026-03-12T02:16:21.943733Z
Summary
hv_netvsc: Fix panic during namespace deletion with VF
Details

In the Linux kernel, the following vulnerability has been resolved:

hv_netvsc: Fix panic during namespace deletion with VF

The existing code move the VF NIC to new namespace when NETDEVREGISTER is received on netvsc NIC. During deletion of the namespace, defaultdeviceexitbatch() >> defaultdeviceexitnet() is called. When netvsc NIC is moved back and registered to the default namespace, it automatically brings VF NIC back to the default namespace. This will cause the defaultdeviceexitnet() >> foreachnetdev_safe loop unable to detect the list end, and hit NULL ptr:

[ 231.449420] mana 7870:00:00.0 enP30832s1: Moved VF to namespace with: eth0 [ 231.449656] BUG: kernel NULL pointer dereference, address: 0000000000000010 [ 231.450246] #PF: supervisor read access in kernel mode [ 231.450579] #PF: errorcode(0x0000) - not-present page [ 231.450916] PGD 17b8a8067 P4D 0 [ 231.451163] Oops: Oops: 0000 [#1] SMP NOPTI [ 231.451450] CPU: 82 UID: 0 PID: 1394 Comm: kworker/u768:1 Not tainted 6.16.0-rc4+ #3 VOLUNTARY [ 231.452042] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 11/21/2024 [ 231.452692] Workqueue: netns cleanupnet [ 231.452947] RIP: 0010:defaultdeviceexitbatch+0x16c/0x3f0 [ 231.453326] Code: c0 0c f5 b3 e8 d5 db fe ff 48 85 c0 74 15 48 c7 c2 f8 fd ca b2 be 10 00 00 00 48 8d 7d c0 e8 7b 77 25 00 49 8b 86 28 01 00 00 <48> 8b 50 10 4c 8b 2a 4c 8d 62 f0 49 83 ed 10 4c 39 e0 0f 84 d6 00 [ 231.454294] RSP: 0018:ff75fc7c9bf9fd00 EFLAGS: 00010246 [ 231.454610] RAX: 0000000000000000 RBX: 0000000000000002 RCX: 61c8864680b583eb [ 231.455094] RDX: ff1fa9f71462d800 RSI: ff75fc7c9bf9fd38 RDI: 0000000030766564 [ 231.455686] RBP: ff75fc7c9bf9fd78 R08: 0000000000000000 R09: 0000000000000000 [ 231.456126] R10: 0000000000000001 R11: 0000000000000004 R12: ff1fa9f70088e340 [ 231.456621] R13: ff1fa9f70088e340 R14: ffffffffb3f50c20 R15: ff1fa9f7103e6340 [ 231.457161] FS: 0000000000000000(0000) GS:ff1faa6783a08000(0000) knlGS:0000000000000000 [ 231.457707] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 231.458031] CR2: 0000000000000010 CR3: 0000000179ab2006 CR4: 0000000000b73ef0 [ 231.458434] Call Trace: [ 231.458600] <TASK> [ 231.458777] opsundolist+0x100/0x220 [ 231.459015] cleanupnet+0x1b8/0x300 [ 231.459285] processonework+0x184/0x340

To fix it, move the ns change to a workqueue, and take rtnllock to avoid changing the netdev list when defaultdeviceexitnet() is using it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38683.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3eb6aa870057da9f1304db660f68b9c2eb7e856d
Fixed
3ca41ab55d23a0aa71661a5a56a8f06c11db90dc
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b7a396f76ada277d049558db648389456458af65
Fixed
3467c4ebb334658c6fcf3eabb64a6e8b2135e010
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4faa6e3e66b3251eb4bf5761d2f3f0f14095aaca
Fixed
4eff1e57a8ef98d70451b94e8437e458b27dd234
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
62c85b9a0dd7471a362170323e1211ad98ff7b4b
Fixed
2a70cbd1aef8b8be39992ab7b776ce1390091774
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4c262801ea60c518b5bebc22a09f5b78b3147da2
Fixed
d036104947176d030bec64792d54e1b4f4c7f318
Fixed
5276896e6923ebe8c68573779d784aaf7d987cce
Fixed
4293f6c5ccf735b26afeb6825def14d830e0367b
Fixed
33caa208dba6fa639e8a92fd0c8320b652e5550c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
7abd221a55a61b6b2bf0e80f850bfc0ae75c7e01
Last affected
31a38a908c98aebc7a1104dab5f1ba199f234b7b
Last affected
04d748d4bd2d86739b159563f257e3dc5492c88d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38683.json"