Database/Kernel, userspace & hypervisor
Linux kernel (ksmbd): Use-after-free in ksmbd session logoff (found by an LLM-assisted audit)
CVSS 4.7CVE-2025-37899Kernel, userspace & hypervisorcurated
Impact
Use-after-free in ksmbd session logoff (found by an LLM-assisted audit)
Who can reach it
Authenticated network to an exposed ksmbd share
What to do
Livepatchable; otherwise drain + reboot. Best answer remains not shipping ksmbd
References
Related entries
- Linux kernel (ksmbd): Use-after-free in ksmbd_tcp_new_connection() - in-kernel SMB serverCVE-2024-26592 · Linux kernel (ksmbd)High
- Linux kernel (drivers/pci/controller): The Hyper-V PCI front-end frees its PCI domain number twice on a probe failureCVE-2026-43097 · Linux kernel (drivers/pci/controller)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/vfio/mdev): If creating an mdev type's sysfs entries partially fails, the parent still registersCVE-2023-52570 · Linux kernel (drivers/vfio/mdev)Medium
- util-linux (wall): WallEscape: escape-sequence injection via wall(1)CVE-2024-28085 · util-linux (wall)Medium
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.