cbcvebase.
CVE-2025-38208
published 2025-07-04

CVE-2025-38208: In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath page is checked for null in…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath page is checked for null in __build_path_from_dentry_optional_prefix when tcon->origin_fullpath is not set. However, the check is missing when it is set. Add a check to prevent a potential NULL pointer dereference.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.2.13 < 6.36.3
linuxlinux>= d5a863a153e90996ab2aef6b9e08d509f4d5662b < 37166d63e42c34846a16001950ecec96229a8d1737166d63e42c34846a16001950ecec96229a8d17
linuxlinux>= d5a863a153e90996ab2aef6b9e08d509f4d5662b < a9e916fa5c7d0ec2256aa44aa24ddd92f529ce35a9e916fa5c7d0ec2256aa44aa24ddd92f529ce35
linuxlinux>= d5a863a153e90996ab2aef6b9e08d509f4d5662b < cce8e71ca1f7ad9045707f0d22490c1e9ed1df6ccce8e71ca1f7ad9045707f0d22490c1e9ed1df6c
linuxlinux>= d5a863a153e90996ab2aef6b9e08d509f4d5662b < f1e7a277a1736e12cc4bd6d93b8a5c439b8ca20cf1e7a277a1736e12cc4bd6d93b8a5c439b8ca20c
linuxlinux_kernel< 6.6.956.6.95
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.7 < 6.12.356.12.35
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.10.78.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
msrccm1_kernel_5.10.60.1-1_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_ubuntu5.6MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.