CVE-2025-38399 | Linux Kernel up to 6.16-rc2 scsi core_scsi3_decode_spec_i_port null pointer dereference (Nessus ID 253428 / WID-SEC-2025-1653)
A vulnerability has been found in Linux Kernel up to 6.16-rc2 and classified as critical. Impacted is the function core_scsi3_decode_spec_i_port of the component scsi. The manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2025-38399. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.