CVE-2025-38737

Advisory lineage Upstream: 0 Downstream: 5
Analyzed
Published: 05 Sept 2025, 17:20
Last modified:11 May 2026, 21:34

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Sept 2025, 17:20
Published
Vulnerability first disclosed
11 May 2026, 21:34
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before calling netfs_alloc_folioq_buffer() as netfs assumes it can append to the buffer it is given. Setting it to NULL means it should start a fresh buffer, but the value is currently undefined.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.02% Percentile: 5%

Techniques & Countermeasures

  • CWE-908Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

Affected Systems

  • linuxlinux

    ≥ a2906d3316fc19bf0ade84618bb73eab604c447e, < 4931fe2dbe1cc0e7d350a4b51b0b330e43971d98 | ≥ a2906d3316fc19bf0ade84618bb73eab604c447e, < 6adaa9fae36f848afa7278945d725e197e33c496 | ≥ a2906d3316fc19bf0ade84618bb73eab604c447e, < 453a6d2a68e54a483d67233c6e1e24c4095ee4be | 6.12

  • linuxlinux_kernel

    ≥ 6.12, < 6.12.44 | ≥ 6.13, < 6.16.4 | 6.17:rc1 | 6.17:rc2

References (3)