CVE-2025-38209 | Linux Kernel up to 6.15.3 nvme_tcp_setup_ctrl use after free (EUVD-2025-20047 / WID-SEC-2025-1465)
A vulnerability has been found in Linux Kernel up to 6.15.3 and classified as critical. This vulnerability affects the function nvme_tcp_setup_ctrl. The manipulation leads to use after free.
This vulnerability is listed as CVE-2025-38209. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.