cbcvebase.
CVE-2025-37924
published 2025-05-20

CVE-2025-37924: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread could be operating on the session and make use of sess->user after it has been passed to ksmbd_free_user but before sess->user is set to NULL.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < e34a33d5d7e87399af0a138bb32f6a3e95dd83d2e34a33d5d7e87399af0a138bb32f6a3e95dd83d2
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < b447463562238428503cfba1c913261047772f90b447463562238428503cfba1c913261047772f90
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < e18c616718018dfc440e4a2d2b94e28fe91b1861e18c616718018dfc440e4a2d2b94e28fe91b1861
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 28c756738af44a404a91b77830d017bb0c52589028c756738af44a404a91b77830d017bb0c525890
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < e86e9134e1d1c90a960dd57f59ce574d27b9a124e86e9134e1d1c90a960dd57f59ce574d27b9a124
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-24.246.14.0-24.24
linuxlinux_kernel>= 5.15 < 6.1.1386.1.138
linuxlinux_kernel>= 6.13 < 6.14.66.14.6
linuxlinux_kernel>= 6.2 < 6.6.906.6.90
linuxlinux_kernel>= 6.7 < 6.12.286.12.28
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH