Security Advisory

CVE-2025-38737

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-05 17:20:37
Last updated 2026-05-11 21:34:01
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before calling netfs_alloc_folioq_buffer() as netfs assumes it can append to the buffer it is given. Setting it to NULL means it should start a fresh buffer, but the value is currently undefined.