CVE-2025-38431

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2025
Last modified:
19/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> smb: client: fix regression with native SMB symlinks<br /> <br /> Some users and customers reported that their backup/copy tools started<br /> to fail when the directory being copied contained symlink targets that<br /> the client couldn&amp;#39;t parse - even when those symlinks weren&amp;#39;t followed.<br /> <br /> Fix this by allowing lstat(2) and readlink(2) to succeed even when the<br /> client can&amp;#39;t resolve the symlink target, restoring old behavior.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.14 (including) 6.15.5 (excluding)
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*