CVE-2025-38122 | Linux Kernel up to 5.15.185/6.1.141/6.6.93/6.12.33/6.15.2 gve_alloc_pending_packet null pointer dereference (EUVD-2025-19821 / Nessus ID 248399)
A vulnerability was found in Linux Kernel up to 5.15.185/6.1.141/6.6.93/6.12.33/6.15.2. It has been declared as critical. Affected is the function gve_alloc_pending_packet. Executing manipulation can lead to null pointer dereference.
This vulnerability appears as CVE-2025-38122. The attacker needs to be present on the local network. There is no available exploit.
It is recommended to upgrade the affected component.