CVE-2025-38374 | Linux Kernel up to 6.12.36/6.15.5/6.16-rc4 optee kernel/locking/mutex.c notif_callback stack-based overflow (Nessus ID 271193 / WID-SEC-2025-1653)
A vulnerability was found in Linux Kernel up to 6.12.36/6.15.5/6.16-rc4 and classified as critical. This vulnerability affects the function notif_callback of the file kernel/locking/mutex.c of the component optee. Executing manipulation can lead to stack-based buffer overflow.
This vulnerability is registered as CVE-2025-38374. The attack requires access to the local network. No exploit is available.
It is suggested to upgrade the affected component.