Security Advisory

CVE-2025-38122

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-03 08:35:28
Last updated 2026-05-11 21:21:40
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: gve: add missing NULL check for gve_alloc_pending_packet() in TX DQO gve_alloc_pending_packet() can return NULL, but gve_tx_add_skb_dqo() did not check for this case before dereferencing the returned pointer. Add a missing NULL check to prevent a potential NULL pointer dereference when allocation fails. This improves robustness in low-memory scenarios.