CVE-2025-38372 | Linux Kernel prior 6.12.37/6.15.6/6.16-rc5 mlx5 __xa_store null pointer dereference (Nessus ID 252237 / WID-SEC-2025-1653)
A vulnerability has been found in Linux Kernel up to 6.12.36/6.15.5/6.16-rc4/edfb65dbb9ffd3102f3ff4dd21316158e56f1976 and classified as critical. This affects the function __xa_store of the component mlx5. Performing manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-38372. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.