cbcvebase.
CVE-2025-21945
published 2025-04-01

CVE-2025-21945: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_lock If smb_lock->zero_len has value, ->llist of smb_lock…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.48%
38.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_lock If smb_lock->zero_len has value, ->llist of smb_lock is not delete and flock is old one. It will cause use-after-free on error handling routine.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 410ce35a2ed6d0e114132bba29af49b69880c8c7410ce35a2ed6d0e114132bba29af49b69880c8c7
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 8573571060ca466cbef2c6f03306b2cc7b8835068573571060ca466cbef2c6f03306b2cc7b883506
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < a0609097fd10d618aed4864038393dd75131289ea0609097fd10d618aed4864038393dd75131289e
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 636e021646cf9b52ddfea7c809b018e91f2188cb636e021646cf9b52ddfea7c809b018e91f2188cb
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 84d2d1641b71dec326e8736a749b7ee76a9599fc84d2d1641b71dec326e8736a749b7ee76a9599fc
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.15 < 6.1.1316.1.131
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83
linuxlinux_kernel>= 6.7 < 6.12.196.12.19
msrcazl3_kernel_6.6.82.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.