CVE-2025-38488
A flaw in the Linux kernel's SMB client can cause the system to crash when using certain hardware crypto accelerators. This happens because the system incorrectly releases memory while a security operation is still being processed in the background.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel, specifically mentioned versions including 6.16 and Debian 11.0, particularly when using hardware crypto accelerators for SMB operations.
Real-world impact
An attacker could potentially trigger a system crash (denial of service) by causing a kernel panic through improper memory management during encrypted communications.
Why this severity
This is rated as critical because the vulnerability allows for a remote, unauthenticated attacker to trigger a kernel crash, leading to a complete loss of system availability.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for CVE-2025-38488.
NVD-referenced vendor advisory
Timeline
- Jul 28, 2025 · Jul 28, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/15a0a5de49507062bc…patch
- git.kernel.org/stable/c/2a76bc2b24ed889a68…patch
- git.kernel.org/stable/c/5d047b12f86cc3b9fd…patch
- git.kernel.org/stable/c/6550b2bef095d0dd2d…patch
- git.kernel.org/stable/c/8ac90f6824fc44d2e5…patch
- git.kernel.org/stable/c/9a1d3e8d40f151c2d5…patch
- git.kernel.org/stable/c/b220bed63330c0e173…patch
- lists.debian.org/debian-lts-announce/2025/10…third party advisory
- lists.debian.org/debian-lts-announce/2025/10…third party advisory