CVE-2025-37826 | Linux Kernel up to 6.12.25/6.14.4/6.15-rc3 scsi ufshcd_mcq_compl_pending_transfer null pointer dereference (Nessus ID 240657 / WID-SEC-2025-0975)
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.25/6.14.4/6.15-rc3. Affected is the function ufshcd_mcq_compl_pending_transfer of the component scsi. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2025-37826. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.