CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-37844: cifs: avoid NULL pointer dereference in dbg call

Description

In the Linux kernel, the following vulnerability has been resolved:

cifs: avoid NULL pointer dereference in dbg call

cifs_server_dbg() implies server to be non-NULL so
move call under condition to avoid NULL pointer dereference.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Classification

CVE ID: CVE-2025-37844

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 7.64% (scored less or equal to compared to others)

EPSS Date: 2025-06-07 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-37844
https://git.kernel.org/stable/c/ba3ce6c60cd5db258687dfeba9fc608f5e7cadf3
https://git.kernel.org/stable/c/9c9000cb91b986eb7f75835340c67857ab97c09b
https://git.kernel.org/stable/c/b2a1833e1c63e2585867ebeaf4dd41494dcede4b
https://git.kernel.org/stable/c/864ba5c651b03830f36f0906c21af05b15c1aaa6
https://git.kernel.org/stable/c/e0717385f5c51e290c2cd2ad4699a778316b5132
https://git.kernel.org/stable/c/20048e658652e731f5cadf4a695925e570ca0ff9
https://git.kernel.org/stable/c/6c14ee6af8f1f188b668afd6d003f7516a507b08
https://git.kernel.org/stable/c/b4885bd5935bb26f0a414ad55679a372e53f9b9b

Timeline