cbcvebase.
CVE-2025-21944
published 2025-04-01

CVE-2025-21944: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix bug on trap in smb2_lock If lock count is greater than 1, flags could be old…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix bug on trap in smb2_lock If lock count is greater than 1, flags could be old value. It should be checked with flags of smb_lock, not flags. It will cause bug-on trap from locks_free_lock in error handling routine.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 11e0e74e14f1832a95092f2c98ed3b99f57797ee11e0e74e14f1832a95092f2c98ed3b99f57797ee
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 8994f0ce8259f812b4f4a681d8298c6ff682efaa8994f0ce8259f812b4f4a681d8298c6ff682efaa
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < dbcd7fdd86f77529210fe8978154a81cd479844cdbcd7fdd86f77529210fe8978154a81cd479844c
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 2b70e3ac79eacbdf32571f7af48dd81cdd957ca82b70e3ac79eacbdf32571f7af48dd81cdd957ca8
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < e26e2d2e15daf1ab33e0135caf2304a0cfa2744be26e2d2e15daf1ab33e0135caf2304a0cfa2744b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.15 < 6.1.1316.1.131
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83
linuxlinux_kernel>= 6.7 < 6.12.196.12.19
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.