CVE-2025-39856

Source
https://cve.org/CVERecord?id=CVE-2025-39856
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39856.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-39856
Downstream
Published
2025-09-19T15:26:27.431Z
Modified
2026-04-02T12:48:11.294159Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
net: ethernet: ti: am65-cpsw-nuss: Fix null pointer dereference for ndev
Details

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: am65-cpsw-nuss: Fix null pointer dereference for ndev

In the TX completion packet stage of TI SoCs with CPSW2G instance, which has single external ethernet port, ndev is accessed without being initialized if no TX packets have been processed. It results into null pointer dereference, causing kernel to crash. Fix this by having a check on the number of TX packets which have been processed.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39856.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9a369ae3d1431a83589dde57323a04692dd7fc12
Fixed
485302905bada953aadfe063320d73c892a66cbb
Fixed
a6099f263e1f408bcc7913c9df24b0677164fc5d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39856.json"