CVE Database
/

CVE-2025-38289

Back to search

CVE-2025-38289

Published: Jul 10, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Avoid potential ndlp use-after-free in dev_loss_tmo_callbk Smatch detected a potential use-after-free of an ndlp oject in dev_loss_tmo_callbk during driver unload or fatal error handling. Fix by reordering code to avoid potential use-after-free if initial nodelist reference has been previously removed.

VendorProductVersions

Linux

Linux

affected
e4913d4bc59227fbdfe6b8f5541f49aaea1cb41c - < ea405fb4144985d5c60f49c2abd9ba47ea44fdb4
affected
4281f44ea8bfedd25938a0031bebba1473ece9ad - < 4f09940b5581e44069eb31a66cf7f05c3c35ed04
affected
4281f44ea8bfedd25938a0031bebba1473ece9ad - < b5162bb6aa1ec04dff4509b025883524b6d7e7ca
affected
6.12.5 - < 6.12.37

Linux

Linux

affected
6.13
unaffected
0 - < 6.13
unaffected
6.12.37 - <= 6.12.*
unaffected
6.15.3 - <= 6.15.*
unaffected
6.16 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now