CVE-2025-37828 | Linux Kernel up to 6.6.88/6.12.25/6.14.4/6.15-rc3 scsi ufshcd_mcq_abort null pointer dereference (Nessus ID 240657 / WID-SEC-2025-0975)
A vulnerability classified as critical was found in Linux Kernel up to 6.6.88/6.12.25/6.14.4/6.15-rc3. Affected by this vulnerability is the function ufshcd_mcq_abort of the component scsi. Such manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2025-37828. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.