Linux · Linux Kernel · CVE-2025-22037
**Name of the Vulnerable Software and Affected Versions**
Linux kernel (affected versions not specified)
**Description**
A null pointer dereference issue in the `alloc preauth hash()` function has been resolved. The issue occurs when a client sends a malformed SMB2 negotiate request, causing the server to return an error response. Subsequently, the client can send an SMB2 session setup request even though the connection's pre-authentication information is not allocated. This allows for potential exploitation.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.