CVE-2025-37899

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/05/2025
Last modified:
24/05/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ksmbd: fix use-after-free in session logoff<br /> <br /> The sess-&gt;user object can currently be in use by another thread, for<br /> example if another connection has sent a session setup request to<br /> bind to the session being free&amp;#39;d. The handler for that connection could<br /> be in the smb2_sess_setup function which makes use of sess-&gt;user.

Impact