CVE-2025-37924
CRITICALLinux Kernel 5.15-6.1.138 6.2.0-6.6.90 6.7.0-6.12.28 6.13.0-6.14.6 - Use-After-Free in Kerberos Authentication
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread could be operating on the session and make use of sess->user after it has been passed to ksmbd_free_user but before sess->user is set to NULL.
References (6)
Core 6
Core References
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html
Scores
CVSS v3
9.8
EPSS
0.0027
EPSS Percentile
50.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (19)
debian/debian_linux
11.0
linux/Kernel
5.15.0 - 6.1.138linux
linux/Kernel
6.13.0 - 6.14.6linux
linux/Kernel
6.2.0 - 6.6.90linux
linux/Kernel
6.7.0 - 6.12.28linux
Linux/Linux
< 5.15
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - 28c756738af44a404a91b77830d017bb0c525890
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - b447463562238428503cfba1c913261047772f90
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - e18c616718018dfc440e4a2d2b94e28fe91b1861
Linux/Linux
0626e6641f6b467447c81dd7678a69c66f7746cf - e34a33d5d7e87399af0a138bb32f6a3e95dd83d2
... and 9 more
Published
May 20, 2025
Tracked Since
Feb 18, 2026