Use of uninitialized resource in Linux kernel - CVE-2025-38737
Published: September 8, 2025
Vulnerability identifier: #VU114953
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-38737
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the smb3_init_transform_rq() function in fs/smb/client/smb2ops.c. A local user can perform a denial of service (DoS) attack.
Affected software
Linux kernel
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
kernel (Red Hat package)
linux (Debian package)
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
kernel (Red Hat package)
linux (Debian package)
How to mitigate CVE-2025-38737
Install update from vendor's repository.
kernel (Red Hat package) - addressed in versions 6.12.0-55.48.1.el10_0, 6.12.0-124.20.1.el10_1
linux (Debian package) - update to 6.12.48-1
linux (Debian package) - update to 6.12.48-1