CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-38737

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-908

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before calling netfs_alloc_folioq_buffer() as netfs assumes it can append to the buffer it is given. Setting it to NULL means it should start a fresh buffer, but the value is currently undefined.

Affected packages

Linux Kernel 6.12.0 → 6.12.44
Linux Kernel 6.13.0 → 6.16.4

References

Status: profiled · ingested 2026-07-30T12:00:00.000Z