CVE-2025-40285
Linux Kernel < 6.1.159, 6.2.0-6.6.117, 6.7.0-6.12.59, 6.13.0-6.17.9 - Reference Count Leak in SMB Session Setup
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().
References (5)
Core 5
Core References
Scores
EPSS
0.0006
EPSS Percentile
17.7%
Details
Status
published
Products (21)
linux/Kernel
< 6.1.159linux
linux/Kernel
6.13.0 - 6.17.9linux
linux/Kernel
6.2.0 - 6.6.117linux
linux/Kernel
6.7.0 - 6.12.59linux
Linux/Linux
< 6.13
Linux/Linux
2107ab40629aeabbec369cf34b8cf0f288c3eb1b
Linux/Linux
37a0e2b362b3150317fb6e2139de67b1e29ae5ff - 6fc935f798d44a8eb8a5e6659198399fbf57b981
Linux/Linux
450a844c045ff0895d41b05a1cbe8febd1acfcfd - e671f9bb97805771380c98de944e2ceab6949188
Linux/Linux
5.15.176 - 5.16
Linux/Linux
6.1.121 - 6.1.159
... and 11 more
Published
Dec 06, 2025
Tracked Since
Feb 18, 2026