Junglewise Threat Intelligence

CVE-2025-38737: Linux Kernel uninitialized variable in CIFS smb3_init_transform_rq

CVE-2025-38737 · Severity: critical · CVSS 9.8 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's CIFS (Common Internet File System) client could cause a system crash or 'kernel oops'. This component is responsible for allowing the operating system to connect to network file shares, such as those provided by Windows or Samba servers. An exploit could lead to a complete loss of system availability or potentially allow unauthorized access to data.

Technical details

The vulnerability is classified as a 'Use of Uninitialized Resource' (CWE-908) within the smb3_init_transform_rq() function in fs/smb/client/smb2ops.c. The function failed to initialize a folio_queue buffer pointer to NULL before passing it to netfs_alloc_folioq_buffer(). Because the netfs utility assumes it can append to an existing buffer if the pointer is non-NULL, the undefined value of the uninitialized variable leads to a kernel oops (crash). This issue was introduced during the transition of crypto buffers from xarrays to folio_queues. Patches have been released for stable kernel branches including 6.12.y and 6.16.y.

Affected products

  • Linux Linux Kernel 6.12 to 6.12.44, 6.13 to 6.16.4, 6.17-rc1, 6.17-rc2

Timeline

  • 2025-08-19: patched: Initial fix commit in Linux kernel tree
  • 2025-09-05: disclosed: CVE published

References

Related threats