-
CVE-2025-37778
- EPSS 0.05%
- Veröffentlicht 01.05.2025 13:07:16
- Zuletzt bearbeitet 03.11.2025 20:18:33
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix dangling pointer in krb_authenticate krb_authenticate frees sess->user and does not set the pointer to NULL. It calls ksmbd_krb5_authenticate to reinitialise sess->user but that function may return without doing so. If that happens then smb2_sess_setup, which calls krb_authenticate, will be accessing free'd memory when it later uses sess->user.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version <
d5b554bc8d554ed6ddf443d3db2fad9f665cec10
Version
0626e6641f6b467447c81dd7678a69c66f7746cf
Status
affected
Version <
1db2451de23e98bc864c6a6e52aa0d82c91cb325
Version
0626e6641f6b467447c81dd7678a69c66f7746cf
Status
affected
Version <
6e30c0e10210c714f3d4453dc258d4abcc70364e
Version
0626e6641f6b467447c81dd7678a69c66f7746cf
Status
affected
Version <
e83e39a5f6a01a81411a4558a59a10f87aa88dd6
Version
0626e6641f6b467447c81dd7678a69c66f7746cf
Status
affected
Version <
1e440d5b25b7efccb3defe542a73c51005799a5f
Version
0626e6641f6b467447c81dd7678a69c66f7746cf
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.15
Status
affected
Version <
5.15
Version
0
Status
unaffected
Version <=
6.1.*
Version
6.1.135
Status
unaffected
Version <=
6.6.*
Version
6.6.88
Status
unaffected
Version <=
6.12.*
Version
6.12.25
Status
unaffected
Version <=
6.14.*
Version
6.14.4
Status
unaffected
Version <=
*
Version
6.15
Status
unaffected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.146 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|