CVE-2025-38092: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_list() The list_first_entry() macro never returns NULL. If the list is empty then it returns an invalid pointer. Use list_first_entry_or_null() to check if the list is empty.
Affected products
- Linux Linux Kernel: from 6.6.88, before 6.6.93 (fixed in 6.6.93); from 6.12.25, before 6.12.32 (fixed in 6.12.32); from 6.14.4, before 6.14.10 (fixed in 6.14.10); version 6.15 only
Published 2025-07-02. Last modified 2026-07-30.