« Volver al listado

CVE-2025-38092

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: use list_first_entry_or_null for opinfo_get_list()

The list_first_entry() macro never returns NULL. If the list is empty then it returns an invalid pointer. Use list_first_entry_or_null() to check if the list is empty.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-38092",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "296cb5457cc6f4a754c4ae29855f8a253d52bcc6",
              "lessThan": "c78abb646ff823e7d22faad4cc0703d4484da9e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d54ab1520d43e95f9b2e22d7a05fc9614192e5a5",
              "lessThan": "334da674b25fdb7a1a4d4b89dcd7795144fc7e11",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d73686367ad68534257cd88a36ca3c52cb8b81d8",
              "lessThan": "cb7e06e9736d73007dc8dab7b353733bb37df86b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "18b4fac5ef17f77fed9417d22210ceafd6525fc7",
              "lessThan": "10379171f346e6f61d30d9949500a8de4336444a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/smb/server/oplock.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6.88",
              "lessThan": "6.6.93",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.25",
              "lessThan": "6.12.32",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.14.4",
              "lessThan": "6.14.10",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/server/oplock.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-02T15:15:26.197",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/10379171f346e6f61d30d9949500a8de4336444a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/334da674b25fdb7a1a4d4b89dcd7795144fc7e11",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c78abb646ff823e7d22faad4cc0703d4484da9e8",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb7e06e9736d73007dc8dab7b353733bb37df86b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use list_first_entry_or_null for opinfo_get_list()\n\nThe list_first_entry() macro never returns NULL.  If the list is\nempty then it returns an invalid pointer.  Use list_first_entry_or_null()\nto check if the list is empty."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ksmbd: usar list_first_entry_or_null para opinfo_get_list(). La macro list_first_entry() nunca devuelve NULL. Si la lista está vacía, devuelve un puntero no válido. Use list_first_entry_or_null() para comprobar si la lista está vacía."
    }
  ],
  "lastModified": "2026-07-30T06:22:50.317",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F54AB024-7562-4452-93AE-645798E55BC9",
              "versionEndExcluding": "6.6.93",
              "versionStartIncluding": "6.6.88"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "832CC9EC-F0C4-4B47-9980-86D9414763B6",
              "versionEndExcluding": "6.12.32",
              "versionStartIncluding": "6.12.25"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5929498-4B70-40E7-98F4-40F6F0D68158",
              "versionEndExcluding": "6.14.10",
              "versionStartIncluding": "6.14.4"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13FC0DDE-E513-465E-9E81-515702D49B74"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C7B5B0E-4EEB-48F5-B4CF-0935A7633845"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D240580-3048-49B2-9E27-F115A9DF8224"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90320558-E553-4EF5-8A0B-0F5D20113BD2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C300BA32-5854-4B59-A00A-18A402F291D0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}