CVE-2025-38501

MEDIUM

Linux Kernel < 6.1.148 - Denial of Service

Title source: rule

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.

Exploits (1)

nomisec WORKING POC 3 stars
by keymaker-arch · poc
https://github.com/keymaker-arch/KSMBDrain

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-400
Status draft

Affected Products (7)

linux/linux_kernel < 6.1.148
debian/debian_linux
linux/Kernel < 6.1.148linux
linux/Kernel < 6.6.102linux
linux/Kernel < 6.12.42linux
linux/Kernel < 6.15.10linux
linux/Kernel < 6.16.1linux

Timeline

Published Aug 16, 2025
Tracked Since Feb 18, 2026