Junglewise Threat Intelligence

CVE-2025-39838: Linux Kernel NULL pointer dereference in CIFS UTF16 conversion

CVE-2025-39838 · Severity: medium · CVSS 5.5 · Published 2025-09-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's CIFS (Common Internet File System) client could allow a local user to crash the system. The issue occurs during the conversion of file names or data to the UTF-16 format used by Windows-compatible network shares. An exploit would result in a kernel panic (system crash), leading to a denial of service and potential loss of unsaved data.

Technical details

A NULL pointer dereference exists in the Linux kernel's CIFS/SMB client implementation. The vulnerability occurs when a NULL pointer is passed to '__cifs_sfu_make_node' without validation, which subsequently flows through 'cifs_strndup_to_utf16' to 'cifs_local_to_utf16_bytes' where it is dereferenced. A local attacker with low privileges can trigger this flaw to cause a kernel oops and system crash (Denial of Service). The issue has been resolved by adding a NULL check in 'cifs_strndup_to_utf16' to return early if the source string is missing.

Affected products

  • Linux Linux Kernel 6.12 to 6.12.46, 6.13 to 6.16.6, 6.17-rc1 to 6.17-rc4

Timeline

  • 2025-09-04: patched: Initial patch submitted to the Linux kernel tree.
  • 2025-09-19: disclosed: CVE-2025-39838 published.
  • 2025-10-13: advisory: Debian LTS advisory DLA-4328-1 released.

References

Related threats