Review reviewHigh

CVE-2025-38734

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() BPF CI testing report a UAF issue: [ 16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003 0 [ 16.447134] #PF: supervisor read access in kernel mod e [ 16.447516] #PF: error_code(0x0000) - not-present pag e [ 16.447878] PGD 0 P4D 0 [ 16.448063] Oops: Oops: 0000 [#1] PREEMPT SMP NOPT I [ 16.448409] CPU: 0 UID: 0 PID: 9 Comm: kworker/0:1 Tainted: G OE 6.13.0-rc3-g89e8a75fda73-dirty #4 2 [ 16.449124] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODUL E [ 16.449502]...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2025.09.06
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() BPF CI testing report a UAF issue: [ 16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003 0 [ 16.447134] #PF: supervisor read access in kernel mod e [ 16.447516] #PF: error_code(0x0000) - not-present pag e [ 16.447878] PGD 0 P4D 0 [ 16.448063] Oops: Oops: 0000 [#1] PREEMPT SMP NOPT I [ 16.448409] CPU: 0 UID: 0 PID: 9 Comm: kworker/0:1 Tainted: G OE 6.13.0-rc3-g89e8a75fda73-dirty #4 2 [ 16.449124] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODUL E [ 16.449502]...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 3b2dec2603d5b06ad3af71c1164ca0b92df3d2a8 < 070b4af44c4b6e4c35fb1ca7001a6a88fd2d318f, >= 3b2dec2603d5b06ad3af71c1164ca0b92df3d2a8 < 2e765ba0ee0eae35688b443e97108308a716773e, >= 3b2dec2603d5b06ad3af71c1164ca0b92df3d2a8 < 85545f1525f9fa9bf44fec77ba011024f15da342, >= 3b2dec2603d5b06ad3af71c1164ca0b92df3d2a8 < d9cef55ed49117bd63695446fb84b4b91815c0b4, >= 4.18, >= 4.18 < 6.6.103, >= 6.7 < 6.12.44, >= 6.13 < 6.16.4, 6.17
Fixed versions
6.6.103, 6.12.44, 6.16.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416