-

CVE-2025-38437

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix potential use-after-free in oplock/lease break ack

If ksmbd_iov_pin_rsp return error, use-after-free can happen by
accessing opinfo->state and opinfo_put and ksmbd_fd_put could
called twice.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < e38ec88a2b42c494601b1213816d75f0b54d9bf0
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 97c355989928a5f60b228ef5266c1be67a46cdf9
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 815f1161d6dbc4c54ccf94b7d3fdeab34b4d7477
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 8106adc21a2270c16abf69cd74ccd7c79c6e7acd
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 50f930db22365738d9387c974416f38a06e8057e
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version < 5.15
Version 0
Status unaffected
Version <= 6.1.*
Version 6.1.146
Status unaffected
Version <= 6.6.*
Version 6.6.99
Status unaffected
Version <= 6.12.*
Version 6.12.39
Status unaffected
Version <= 6.15.*
Version 6.15.7
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String