PT-2025-17275 · Linux+5 · Linux Kernel+5

Published

2025-03-27

·

Updated

2026-05-22

·

CVE-2025-38575

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.135-1 Linux kernel versions prior to 6.1.137-1~deb11u1 Linux kernel versions prior to 6.6.88 Linux kernel (HWE) (affected versions not specified) Linux kernel (Azure) (affected versions not specified) Linux kernel (Oracle) (affected versions not specified) Linux kernel (OEM) (affected versions not specified) Linux kernel (AWS) (affected versions not specified) Linux kernel (Low Latency) (affected versions not specified)
Description Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, or information leaks. A specific issue, identified as CVE-2025-38575, exists within the ksmbd module, related to improper memory management. Specifically, the ksmbd crypt message() function and the aead request free() function were not used correctly, leading to a use-after-free condition. This could allow an attacker to gain access to sensitive cryptographic data. The upstream kernel version 6.6.87 and 6.6.88 include fixes for bugs and vulnerabilities. The kmod-virtualbox and kmod-xtables-addons packages have been updated to work with the new kernel.
Recommendations Upgrade to Linux kernel version 6.1.135-1 or later. Upgrade to Linux kernel version 6.1.137-1~deb11u1 or later for Debian 11 bullseye. Upgrade to Linux kernel version 6.6.88 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for Linux kernel (HWE). At the moment, there is no information about a newer version that contains a fix for this vulnerability for Linux kernel (Azure). At the moment, there is no information about a newer version that contains a fix for this vulnerability for Linux kernel (Oracle). At the moment, there is no information about a newer version that contains a fix for this vulnerability for Linux kernel (OEM). At the moment, there is no information about a newer version that contains a fix for this vulnerability for Linux kernel (AWS). At the moment, there is no information about a newer version that contains a fix for this vulnerability for Linux kernel (Low Latency).

Exploit

Fix

Use After Free

Improper Resource Release

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12063
CVE-2025-38575
DLA-4193-1
DSA-5907-1
ECHO-FB9B-2F3D-2407
MGASA-2025-0142
MGASA-2025-0146
OESA-2026-2417
OESA-2026-2418
USN-7591-1
USN-7591-2
USN-7591-3
USN-7591-4
USN-7591-5
USN-7591-6
USN-7592-1
USN-7593-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7597-1
USN-7597-2
USN-7598-1
USN-7602-1
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7655-1
USN-7835-1
USN-7835-2
USN-7835-3
USN-7835-4
USN-7835-5
USN-7835-6
USN-7887-1
USN-7887-2
USN-7940-1
USN-7940-2

Affected Products

Astra Linux
Debian
Linux Kernel
Linuxmint
Red Os
Ubuntu