CVE-2025-37844
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
09/05/2025
Last modified:
17/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
cifs: avoid NULL pointer dereference in dbg call<br />
<br />
cifs_server_dbg() implies server to be non-NULL so<br />
move call under condition to avoid NULL pointer dereference.<br />
<br />
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.6.7 (including) | 5.10.237 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.181 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.135 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.88 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.13.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.14 (including) | 6.14.3 (excluding) |
| cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/20048e658652e731f5cadf4a695925e570ca0ff9
- https://git.kernel.org/stable/c/6c14ee6af8f1f188b668afd6d003f7516a507b08
- https://git.kernel.org/stable/c/864ba5c651b03830f36f0906c21af05b15c1aaa6
- https://git.kernel.org/stable/c/9c9000cb91b986eb7f75835340c67857ab97c09b
- https://git.kernel.org/stable/c/b2a1833e1c63e2585867ebeaf4dd41494dcede4b
- https://git.kernel.org/stable/c/b4885bd5935bb26f0a414ad55679a372e53f9b9b
- https://git.kernel.org/stable/c/ba3ce6c60cd5db258687dfeba9fc608f5e7cadf3
- https://git.kernel.org/stable/c/e0717385f5c51e290c2cd2ad4699a778316b5132
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html



