CVE-2025-37844: cifs: avoid NULL pointer dereference in dbg call
Published May 9, 2025
·Updated
cifs: avoid NULL pointer dereference in dbg call
Affected Software
11 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=5.6.7<5.10.237
Linux Linux kernel>=5.11<5.15.181
Linux Linux kernel>=5.16<6.1.135
Linux Linux kernel>=6.2<6.6.88
Linux Linux kernel>=6.7<6.12.24
Linux Linux kernel>=6.13<6.13.12
Linux Linux kernel>=6.14<6.14.3
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.85.1-4
Microsoft azl3 kernel 6.6.92.2-1
Remediation
Event History
May 9, 2025
CVE Published
via MITRE·06:41 AM
Data Sourced
via MITRE·06:41 AM
Description
Data Sourced
via NVD·07:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 11, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-37844?
CVE-2025-37844 is classified as a low severity vulnerability affecting the Linux kernel.
2
How do I fix CVE-2025-37844?
To fix CVE-2025-37844, ensure that you upgrade to the latest version of the Linux kernel where the vulnerability has been addressed.
3
What systems are affected by CVE-2025-37844?
CVE-2025-37844 affects various versions of the Linux kernel that implement the CIFS (Common Internet File System) protocol.
4
What type of threat does CVE-2025-37844 pose?
CVE-2025-37844 poses a threat of a NULL pointer dereference, potentially leading to a denial of service condition.
5
Who discovered CVE-2025-37844?
CVE-2025-37844 was discovered by the Linux Verification Center.