CVE-2025-38695

Source
https://cve.org/CVERecord?id=CVE-2025-38695
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38695.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38695
Downstream
Related
Published
2025-09-04T15:32:48.168Z
Modified
2026-03-12T02:16:29.799593Z
Summary
scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure

If a call to lpfcsli4readrev() from lpfcsli4hbasetup() fails, the resultant cleanup routine lpfcsli4vportdeletefcpxriaborted() may occur before sli4hba.hdwqs are allocated. This may result in a null pointer dereference when attempting to take the abtsiobuflistlock for the first hardware queue. Fix by adding a null ptr check on phba->sli4hba.hdwq and early return because this situation means there must have been an error during port initialization.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38695.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5e5b511d8bfaf765cb92a695cda336c936cb86dc
Fixed
6711ce7e9de4eb1a541ef30638df1294ea4267f8
Fixed
74bdf54a847dab209d2a8f65852f59b7fa156175
Fixed
5e25ee1ecec91c61a8acf938ad338399cad464de
Fixed
add68606a01dcccf18837a53e85b85caf0693b4b
Fixed
7925dd68807cc8fd755b04ca99e7e6f1c04392e8
Fixed
571617f171f723b05f02d154a2e549a17eab4935
Fixed
d3f55f46bb37a8ec73bfe3cfe36e3ecfa2945dfa
Fixed
46a0602c24d7d425dd8e00c749cd64a934aac7ec
Fixed
6698796282e828733cde3329c887b4ae9e5545e9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38695.json"