CVE-2025-38431

MEDIUM

Linux Kernel 6.14-6.15.4 - Denial of Service via SMB Symlink Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix regression with native SMB symlinks Some users and customers reported that their backup/copy tools started to fail when the directory being copied contained symlink targets that the client couldn't parse - even when those symlinks weren't followed. Fix this by allowing lstat(2) and readlink(2) to succeed even when the client can't resolve the symlink target, restoring old behavior.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (9)
linux/Kernel 6.14.0 - 6.15.5linux
Linux/Linux < 6.14
Linux/Linux 12b466eb52d926802b6898d2cb7e67386467f54a - 6ddaf7567080c7de2e0c99efca2ee1e6b79beea5
Linux/Linux 12b466eb52d926802b6898d2cb7e67386467f54a - ff8abbd248c1f52df0c321690b88454b13ff54b2
Linux/Linux 6.14
Linux/Linux 6.15.5 - 6.15.*
Linux/Linux 6.16
linux/linux_kernel 6.16 rc1 (3 CPE variants)
linux/linux_kernel 6.14 - 6.15.5
Published Jul 25, 2025
Tracked Since Feb 18, 2026