CVE-2025-38035 | Linux Kernel up to 6.14.8 TCP Connection nvmet_tcp_set_queue_sock null pointer dereference (Nessus ID 242347 / WID-SEC-2025-1350)
A vulnerability was found in Linux Kernel up to 6.14.8. It has been classified as critical. Affected is the function nvmet_tcp_set_queue_sock of the component TCP Connection Handler. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2025-38035. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is recommended.