SB2025072743 - NULL pointer dereference in Linux kernel target driver
Published: July 27, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-38399)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the kmem_cache_free() function in drivers/target/target_core_pr.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1129e0e0a833acf90429e0f13951068d5f026e4f
- https://git.kernel.org/stable/c/1627dda4d70ceb1ba62af2e401af73c09abb1eb5
- https://git.kernel.org/stable/c/55dfffc5e94730370b08de02c0cf3b7c951bbe9e
- https://git.kernel.org/stable/c/70ddb8133fdb512d4b1f2b4fd1c9e518514f182c
- https://git.kernel.org/stable/c/7296c938df2445f342be456a6ff0b3931d97f4e5
- https://git.kernel.org/stable/c/c412185d557578d3f936537ed639c4ffaaed4075
- https://git.kernel.org/stable/c/d8ab68bdb294b09a761e967dad374f2965e1913f