CVE-2025-21945
HIGHLinux Kernel 5.15-6.1.130, 6.2.0-6.6.82, 6.7.0-6.12.18, 6.13.0-6.13.6 - Use-After-Free in SMB2 Lock Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_lock If smb_lock->zero_len has value, ->llist of smb_lock is not delete and flock is old one. It will cause use-after-free on error handling routine.
References (6)
Core 6
Core References
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
7.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (18)
linux/Kernel
5.15.0 - 6.1.131linux
linux/Kernel
6.13.0 - 6.13.7linux
linux/Kernel
6.2.0 - 6.6.83linux
linux/Kernel
6.7.0 - 6.12.19linux
Linux/Linux
< 5.15
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - 410ce35a2ed6d0e114132bba29af49b69880c8c7
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - 636e021646cf9b52ddfea7c809b018e91f2188cb
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - 84d2d1641b71dec326e8736a749b7ee76a9599fc
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - 8573571060ca466cbef2c6f03306b2cc7b883506
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - a0609097fd10d618aed4864038393dd75131289e
... and 8 more
Published
Apr 01, 2025
Tracked Since
Feb 18, 2026