A vulnerability has been found in Linux Kernel up to 6.16.7 and classified as critical. The affected element is the function rtl9300_i2c_config_xfer of the component SFP Module. This manipulation causes missing initialization of a variable.

This vulnerability is tracked as CVE-2025-39928. The attack is only possible within the local network. No exploit exists.

The affected component should be upgraded.