CVE-2025-37820 | Linux Kernel up to 6.1.135/6.6.88/6.12.25/6.14.4/6.15-rc3 xen-netfront xdp_convert_buff_to_frame null pointer dereference (Nessus ID 237504 / WID-SEC-2025-0975)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.135/6.6.88/6.12.25/6.14.4/6.15-rc3. The impacted element is the function xdp_convert_buff_to_frame of the component xen-netfront. Executing manipulation can lead to null pointer dereference.
This vulnerability is handled as CVE-2025-37820. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.