CVE-2025-38191 | Linux Kernel up to 6.1.141/6.6.94/6.12.34/6.15.3/6.16-rc2 ksmbd ksmbd_krb5_authenticate User null pointer dereference (EUVD-2025-20065 / Nessus ID 249177)
A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.141/6.6.94/6.12.34/6.15.3/6.16-rc2. This impacts the function ksmbd_krb5_authenticate of the component ksmbd. The manipulation of the argument User leads to null pointer dereference.
This vulnerability is traded as CVE-2025-38191. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.