CVE-2025-38325

MEDIUM

Linux Kernel - Use-After-Free in ksmbd Connection Transport

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add free_transport ops in ksmbd connection free_transport function for tcp connection can be called from smbdirect. It will cause kernel oops. This patch add free_transport ops in ksmbd connection, and add each free_transports for tcp and smbdirect.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 5.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (17)
linux/Kernel < 6.12.35linux
linux/Kernel 6.13.0 - 6.15.4linux
Linux/Linux < 6.15
Linux/Linux 1aec4d14cf81b7b3e7b69eb1cfa94144eed7138e - 3890da762a66191c440b0bd6e3ee45501edbb0c1
Linux/Linux 1da8bd9a10ecd718692732294d15fd801c0eabb5 - 52f5a52dc17a4a7b4363ac03fe2c4ef26f020dc6
Linux/Linux 21a4e47578d44c6b37c4fc4aba8ed7cc8dbb13de - 3f3aae77280aad9f5acc6709c596148966f765c7
Linux/Linux 21a4e47578d44c6b37c4fc4aba8ed7cc8dbb13de - a89f5fae998bdc4d0505306f93844c9ae059d50c
Linux/Linux 6.12.26 - 6.12.35
Linux/Linux 6.12.35 - 6.12.*
Linux/Linux 6.14.4 - 6.15
... and 7 more
Published Jul 10, 2025
Tracked Since Feb 18, 2026