CVE-2025-37826 | Linux Kernel up to 6.12.25/6.14.4/6.15-rc3 scsi ufshcd_mcq_compl_pending_transfer null pointer dereference (Nessus ID 240657)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.25/6.14.4/6.15-rc3. Affected by this issue is the function ufshcd_mcq_compl_pending_transfer of the component scsi. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-37826. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.