CVE-2025-38628 | Linux Kernel up to 6.12.41/6.15.9/6.16.0 vdpa mlx5_vdpa_free uninitialized resource (Nessus ID 270575 / WID-SEC-2025-1898)
A vulnerability classified as problematic was found in Linux Kernel up to 6.12.41/6.15.9/6.16.0. This affects the function mlx5_vdpa_free of the component vdpa. Executing a manipulation can lead to uninitialized resource.
This vulnerability is handled as CVE-2025-38628. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.