
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38695 is a vulnerability discovered in the Linux kernel affecting the SCSI lpfc driver. The vulnerability was disclosed on September 4, 2025, and involves a potential null pointer dereference in the lpfc_vport structure cleanup process (NVD).
The vulnerability occurs when a call to lpfcsli4readrev() from lpfcsli4hbasetup() fails, causing the cleanup routine lpfcsli4vportdeletefcpxriaborted() to execute before sli4hba.hdwqs are allocated. This can result in a null pointer dereference when attempting to take the abtsiobuflist_lock for the first hardware queue. The vulnerability has been assigned a CVSS v3 base score of 7.0, indicating moderate severity (Rapid7).
If exploited, this vulnerability could lead to a system crash due to the null pointer dereference, potentially causing a denial of service condition in affected Linux systems running the lpfc driver (NVD).
The fix involves adding a null pointer check on phba->sli4_hba.hdwq and implementing an early return mechanism when an error occurs during port initialization. This patch has been integrated into the Linux kernel (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."