-

CVE-2025-38437

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix potential use-after-free in oplock/lease break ack

If ksmbd_iov_pin_rsp return error, use-after-free can happen by
accessing opinfo->state and opinfo_put and ksmbd_fd_put could
called twice.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < e38ec88a2b42c494601b1213816d75f0b54d9bf0
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 97c355989928a5f60b228ef5266c1be67a46cdf9
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 815f1161d6dbc4c54ccf94b7d3fdeab34b4d7477
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 8106adc21a2270c16abf69cd74ccd7c79c6e7acd
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 50f930db22365738d9387c974416f38a06e8057e
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.15
Status affected
Version < 5.15
Version 0
Status unaffected
Version <= 6.1.*
Version 6.1.146
Status unaffected
Version <= 6.6.*
Version 6.6.99
Status unaffected
Version <= 6.12.*
Version 6.12.39
Status unaffected
Version <= 6.15.*
Version 6.15.7
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.061
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string