Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-37844

17
FAUCET Score

CVE-2025-37844 is a NULL pointer dereference vulnerability in the Linux kernel's CIFS module, affecting various Debian and Linux kernel versions. This flaw, identified by the Linux Verification Center, occurs when the cifs_server_dbg() function is called with a NULL server pointer. Rated Medium (CVSS 5.5), it allows a local attacker with low privileges to cause a denial of service (system crash) with low attack complexity. There is no evidence of active exploitation, and no public exploit code is available, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.6.7, < 5.10.237CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.181CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.135CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.88CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.12.24CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 66th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.85.1-4 on Azure Linux 3.0Fixed in: 6.6.92.2-1
microsoftpatch availablevia msrc
Product: 19529-17084Fixed in: 6.6.92.2-1
microsoftpatch availablevia msrc
Product: 19734-17084Fixed in: 6.6.92.2-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.92.2-1 on Azure Linux 3.0Fixed in: 6.6.92.2-1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (10)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
microsoft2025-May/CVE-2025-37844Moderate

cifs: avoid NULL pointer dereference in dbg call

May 13, 2025
redhatCVE-2025-37844Moderate

kernel: cifs: avoid NULL pointer dereference in dbg call

May 9, 2025

References

git.kernel.org / stable/c/20048e658652e731f5cadf4a695925e570ca0ff9
Patch
git.kernel.org / stable/c/6c14ee6af8f1f188b668afd6d003f7516a507b08
Patch
git.kernel.org / stable/c/864ba5c651b03830f36f0906c21af05b15c1aaa6
Patch
git.kernel.org / stable/c/9c9000cb91b986eb7f75835340c67857ab97c09b
Patch
git.kernel.org / stable/c/b2a1833e1c63e2585867ebeaf4dd41494dcede4b
Patch
git.kernel.org / stable/c/b4885bd5935bb26f0a414ad55679a372e53f9b9b
Patch
git.kernel.org / stable/c/ba3ce6c60cd5db258687dfeba9fc608f5e7cadf3
Patch
git.kernel.org / stable/c/e0717385f5c51e290c2cd2ad4699a778316b5132
Patch
lists.debian.org / debian-lts-announce/2025/05/msg00030.html
Mailing List
lists.debian.org / debian-lts-announce/2025/05/msg00045.html
Mailing List