CVE-2025-38526: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ice: add NULL check in eswitch lag check The function ice_lag_is_switchdev_running() is being called from outside of the LAG event handler code. This results in the lag->upper_netdev being NULL sometimes. To avoid a NULL-pointer dereference, there needs to be a check before it is dereferenced.
Affected products
- Linux Linux Kernel: from 6.6.1, before 6.6.100 (fixed in 6.6.100); from 6.7, before 6.12.40 (fixed in 6.12.40); from 6.13, before 6.15.8 (fixed in 6.15.8); version 6.6 only; version 6.16 only
Published 2025-08-16. Last modified 2026-07-30.