imPC@ndo IT

Tracker / CVE-2025-38737

CVE-2025-38737

Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before calling netfs_alloc_folioq_buffer() as netfs assumes it can append to the buffer it is given. Setting it to NULL means it should start a fresh buffer, but the value is currently undefined.

Affected products and versions

linux linux_kernel
linux linux_kernel · 6.12 → 6.12.44
linux linux_kernel · 6.13 → 6.16.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References