CVE-2025-38191 | Linux Kernel up to 6.1.141/6.6.94/6.12.34/6.15.3/6.16-rc2 ksmbd ksmbd_krb5_authenticate User null pointer dereference (EUVD-2025-20065)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.141/6.6.94/6.12.34/6.15.3/6.16-rc2. Affected is the function ksmbd_krb5_authenticate of the component ksmbd. The manipulation of the argument User leads to null pointer dereference.
This vulnerability is traded as CVE-2025-38191. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.