cbcvebase.
CVE-2025-22041
published 2025-04-16

CVE-2025-22041: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue…

PriorityP344high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.60%
44.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can occur in session_deregister when the second channel sets up a session through the connection of the first channel. session that is freed through the global session table can be accessed again through ->sessions of connection.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < f0eb3f575138b816da74697bd506682574742fcdf0eb3f575138b816da74697bd506682574742fcd
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < a8a8ae303a8395cbac270b5b404d85df6ec788f8a8a8ae303a8395cbac270b5b404d85df6ec788f8
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < ca042cc0e4f9e0d2c8f86dd67e4b22f30a516a9bca042cc0e4f9e0d2c8f86dd67e4b22f30a516a9b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 8ed0e9d2f410f63525afb8351181eea36c80bcf18ed0e9d2f410f63525afb8351181eea36c80bcf1
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 33cc29e221df7a3085ae413e8c26c4e81a15115333cc29e221df7a3085ae413e8c26c4e81a151153
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 15a9605f8d69dc85005b1a00c31a050b8625e1aa15a9605f8d69dc85005b1a00c31a050b8625e1aa
linuxlinux_kernel< 6.1.1346.1.134
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.2 < 6.6.876.6.87
linuxlinux_kernel>= 6.7 < 6.12.136.12.13
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.