CVE-2025-38289

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
10/07/2025
Last modified:
19/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> scsi: lpfc: Avoid potential ndlp use-after-free in dev_loss_tmo_callbk<br /> <br /> Smatch detected a potential use-after-free of an ndlp oject in<br /> dev_loss_tmo_callbk during driver unload or fatal error handling.<br /> <br /> Fix by reordering code to avoid potential use-after-free if initial<br /> nodelist reference has been previously removed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.12.5 (including) 6.12.37 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.15.3 (excluding)