Junglewise Threat Intelligence

CVE-2025-38695: Linux Kernel lpfc null pointer dereference in SCSI cleanup

CVE-2025-38695 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Emulex LightPulse Fibre Channel (lpfc) driver could allow a local user to cause a system crash. The issue occurs during specific hardware initialization failures, where the system attempts to clean up resources that haven't been fully set up yet. This results in a 'null pointer dereference,' leading to a kernel panic and loss of system availability.

Technical details

A NULL pointer dereference exists in the lpfc driver within the SCSI subsystem of the Linux kernel. The vulnerability occurs in the lpfc_sli4_vport_delete_fcp_xri_aborted() function. If lpfc_sli4_read_rev() fails during HBA setup, the cleanup routine is triggered before the sli4_hba.hdwqs hardware queues are allocated. When the routine attempts to acquire the abts_io_buf_list_lock for the first hardware queue, it dereferences a NULL pointer. This is a local attack vector requiring low privileges, resulting in a kernel panic (DoS). Patches have been merged into various stable kernel branches.

Affected products

  • Linux Linux Kernel 5.1 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-06-18: other: Patch submitted by developer
  • 2025-09-04: disclosed: CVE published

References

Related threats