PT-2025-22161 · Linux+5 · Linux Kernel+5

Published

2025-04-21

·

Updated

2026-05-26

·

CVE-2025-37899

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel ksmbd module (affected versions not specified)
Description A use-after-free issue exists in the ksmbd module, which provides an in-kernel implementation of the SMB (Server Message Block) file server. The flaw is located in the smb2 sess setup() function within the fs/smb/server/smb2pdu.c module, specifically during the handling of the SMB logoff command. The sess->user object can be accessed by another thread if a session setup request is sent to bind to a session that is currently being freed. This memory safety error could allow a remote attacker to cause a denial of service (system crash) or potentially execute arbitrary code with kernel privileges, which could lead to root access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

RCE

DoS

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-06026
CVE-2025-37899
ECHO-1E9D-9C2B-8B11
USN-7649-1
USN-7649-2
USN-7650-1
USN-7665-1
USN-7665-2
USN-7721-1
USN-8059-1
USN-8059-2
USN-8059-3
USN-8059-4
USN-8059-5
USN-8059-6
USN-8059-7
USN-8059-8
USN-8059-9
USN-8125-1
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu