PT-2025-33760 · Linux+5 · Linux Kernel+5
Nicholas Zubrisky
+1
·
Published
2025-07-24
·
Updated
2026-04-20
·
CVE-2025-38561
CVSS v3.1
8.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel versions prior to the fix
Description
The issue relates to a race condition within the
Preauh HashValue() function of the ksmbd component in the Linux kernel. This occurs when a client sends multiple session setup requests to ksmbd. The problem stems from incorrect synchronization when a shared resource is used. The vulnerability could allow an attacker to cause a denial of service. The vulnerable function is Preauh HashValue(). The sess->Preauh HashValue variable is involved in the race condition.Recommendations
Update the Linux Kernel to the version containing the fix for this vulnerability.
Exploit
Fix
RCE
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu