CVE-2025-37776

HIGH

Linux Kernel 5.15-6.6.87, 6.7-6.12.24, 6.13-6.14.3 - Use-After-Free in smb_break_all_levII_oplock

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use read lock to protect whole loop.

Scores

CVSS v3 7.0
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (15)
linux/Kernel 5.15.0 - 6.6.88linux
linux/Kernel 6.13.0 - 6.14.4linux
linux/Kernel 6.7.0 - 6.12.25linux
Linux/Linux < 5.15
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 18b4fac5ef17f77fed9417d22210ceafd6525fc7
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 296cb5457cc6f4a754c4ae29855f8a253d52bcc6
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - d54ab1520d43e95f9b2e22d7a05fc9614192e5a5
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - d73686367ad68534257cd88a36ca3c52cb8b81d8
Linux/Linux 5.15
Linux/Linux 6.12.25 - 6.12.*
... and 5 more
Published May 01, 2025
Tracked Since Feb 18, 2026