cbcvebase.
CVE-2025-38270
published 2025-07-10

CVE-2025-38270: In the Linux kernel, the following vulnerability has been resolved: net: drv: netdevsim: don't napi_complete() from netpoll netdevsim supports netpoll. Make…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: drv: netdevsim: don't napi_complete() from netpoll netdevsim supports netpoll. Make sure we don't call napi_complete() from it, since it may not be scheduled. Breno reports hitting a warning in napi_complete_done(): WARNING: CPU: 14 PID: 104 at net/core/dev.c:6592 napi_complete_done+0x2cc/0x560 __napi_poll+0x2d8/0x3a0 handle_softirqs+0x1fe/0x710 This is presumably after netpoll stole the SCHED bit prematurely.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux>= 3762ec05a9fbda16aaaa2568df679ab8ad13f38d < a8ff2e362d901200a1075c3ca9c56d9c7bbef389a8ff2e362d901200a1075c3ca9c56d9c7bbef389
linuxlinux>= 3762ec05a9fbda16aaaa2568df679ab8ad13f38d < 6837dd877270c57689bd866de9f3de14172c24396837dd877270c57689bd866de9f3de14172c2439
linuxlinux>= 3762ec05a9fbda16aaaa2568df679ab8ad13f38d < 1264971017b4d7141352a7fe29021bdfce5d885d1264971017b4d7141352a7fe29021bdfce5d885d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 6.10 < 6.12.346.12.34
linuxlinux_kernel>= 6.13 < 6.15.36.15.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.