CVE-2025-38570: eth: fbnic: unlink NAPIs from queues on error to open

Published Aug 19, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

eth: fbnic: unlink NAPIs from queues on error to open

CI hit a UaF in fbnic in the AFXDP portion of the queues.py test. The UaF is in the skmarknapiidonce() call in xskbind(), NAPI has been freed. Looks like the device failed to open earlier, and we lack clearing the NAPI pointer from the queue.

Affected Software

3 affected components
Linux Linux kernel
Linux Linux kernel>=6.14<6.15.10
Linux Linux kernel>=6.16<6.16.1

Event History

Aug 19, 2025
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-38570?

CVE-2025-38570 has been identified as having a high severity due to the potential for use-after-free vulnerabilities in the Linux kernel.

2

How do I fix CVE-2025-38570?

To fix CVE-2025-38570, update your Linux kernel to the latest stable version where the vulnerability has been patched.

3

Which versions of the Linux kernel are affected by CVE-2025-38570?

CVE-2025-38570 affects multiple versions of the Linux kernel, specifically those prior to the fix implemented in the recent updates.

4

What components of the Linux kernel are impacted by CVE-2025-38570?

CVE-2025-38570 impacts the Ethernet subsystem, particularly the fbnic driver and the AF_XDP portion of the queues.

5

What actions should I take if my system is vulnerable to CVE-2025-38570?

If your system is vulnerable to CVE-2025-38570, it is crucial to apply security patches and updates immediately to mitigate potential risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203