In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in __smb2_lease_break_noti()
Move tcp_transport free to ksmbd_conn_free. If ksmbd connection is
referenced when ksmbd server thread terminates, It will not be freed,
but conn->tcp_transport is freed. __smb2_lease_break_noti can be performed
asynchronously when the connection is disconnected. __smb2_lease_break_noti
calls ksmbd_conn_write, which can cause use-after-free
when conn->ksmbd_transport is already freed.
CVSS
No CVSS.
References
Configurations
No configuration.
History
01 Aug 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 May 2025, 13:53
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
02 May 2025, 07:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-01 14:15
Updated : 2025-08-01 09:15
NVD link : CVE-2025-37777
Mitre link : CVE-2025-37777
CVE.ORG link : CVE-2025-37777
JSON object : View
Products Affected
No product.
CWE
No CWE.