CVE-2025-39838
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/09/2025
Última modificación:
19/09/2025
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
cifs: prevent NULL pointer dereference in UTF16 conversion<br />
<br />
There can be a NULL pointer dereference bug here. NULL is passed to<br />
__cifs_sfu_make_node without checks, which passes it unchecked to<br />
cifs_strndup_to_utf16, which in turn passes it to<br />
cifs_local_to_utf16_bytes where &#39;*from&#39; is dereferenced, causing a crash.<br />
<br />
This patch adds a check for NULL &#39;src&#39; in cifs_strndup_to_utf16 and<br />
returns NULL early to prevent dereferencing NULL pointer.<br />
<br />
Found by Linux Verification Center (linuxtesting.org) with SVACE
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/1cfa5dd05847137f0fb3ce74ced80c0b4858d716
- https://git.kernel.org/stable/c/1f797f062b5cf13a1c2bcc23285361baaa7c9260
- https://git.kernel.org/stable/c/3c26a8d30ed6b53a52a023ec537dc50a6d34a67a
- https://git.kernel.org/stable/c/65b98a7e65e7a8f3894d8760cd194eaf20504c99
- https://git.kernel.org/stable/c/70bccd9855dae56942f2b18a08ba137bb54093a0