CVE-2025-37924

CRITICAL

Linux Kernel 5.15-6.1.138 6.2.0-6.6.90 6.7.0-6.12.28 6.13.0-6.14.6 - Use-After-Free in Kerberos Authentication

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread could be operating on the session and make use of sess->user after it has been passed to ksmbd_free_user but before sess->user is set to NULL.

Scores

CVSS v3 9.8
EPSS 0.0027
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (19)
debian/debian_linux 11.0
linux/Kernel 5.15.0 - 6.1.138linux
linux/Kernel 6.13.0 - 6.14.6linux
linux/Kernel 6.2.0 - 6.6.90linux
linux/Kernel 6.7.0 - 6.12.28linux
Linux/Linux < 5.15
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 28c756738af44a404a91b77830d017bb0c525890
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - b447463562238428503cfba1c913261047772f90
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - e18c616718018dfc440e4a2d2b94e28fe91b1861
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - e34a33d5d7e87399af0a138bb32f6a3e95dd83d2
... and 9 more
Published May 20, 2025
Tracked Since Feb 18, 2026