CVE-2025-38437 | Linux Kernel up to 6.1.145/6.6.98/6.12.38/6.15.6/6.16-rc5 ksmbd ksmbd_iov_pin_rsp use after free
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.145/6.6.98/6.12.38/6.15.6/6.16-rc5. Affected is the function ksmbd_iov_pin_rsp of the component ksmbd. The manipulation leads to use after free.
This vulnerability is traded as CVE-2025-38437. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.