CVE-2025-38737: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before calling netfs_alloc_folioq_buffer() as netfs assumes it can append to the buffer it is given. Setting it to NULL means it should start a fresh buffer, but the value is currently undefined.
Affected products
- Linux Linux Kernel: from 6.12, before 6.12.44 (fixed in 6.12.44); from 6.13, before 6.16.4 (fixed in 6.16.4); version 6.17 only
Published 2025-09-05. Last modified 2026-07-30.