cbcvebase.
CVE-2025-37962
published 2025-05-20

CVE-2025-37962: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bounds check…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bounds check for create lease context introduced a memory leak. When the bounds check fails, the function returns NULL without freeing the previously allocated lease_ctx_info structure. This patch fixes the issue by adding kfree(lreq) before returning NULL in both boundary check cases.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= 6.1.134 < 6.1.1396.1.139
linuxlinux>= 6.12.23 < 6.12.296.12.29
linuxlinux>= 6.13.11 < 6.146.14
linuxlinux>= 6.14.2 < 6.14.76.14.7
linuxlinux>= 6.6.87 < 6.6.916.6.91
linuxlinux>= 60b7207893a8a06c78441934931a08fdad63f18e < af9e2d4732a548db8f6f5a90c2c20a789a3d7240af9e2d4732a548db8f6f5a90c2c20a789a3d7240
linuxlinux>= 629dd37acc336ad778979361c351e782053ea284 < facf22c1a394c1e023dab5daf9a494f722771e1cfacf22c1a394c1e023dab5daf9a494f722771e1c
linuxlinux>= 800c482c9ef5910f05e3a713943c67cc6c1d4939 < 2148d34371b06dac696c0497a98a6bf905a516502148d34371b06dac696c0497a98a6bf905a51650
linuxlinux>= 9a1b6ea955e6c7b29939a6d98701202f9d9644ec < 829e19ef741d9e9932abdc3bee5466195e0852cf829e19ef741d9e9932abdc3bee5466195e0852cf
linuxlinux>= bab703ed8472aa9d109c5f8c1863921533363dae < eb4447bcce915b43b691123118893fca4f372a8feb4447bcce915b43b691123118893fca4f372a8f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.1.134 < 6.1.1396.1.139
linuxlinux_kernel>= 6.12.23 < 6.12.296.12.29
linuxlinux_kernel>= 6.13.11 < 6.146.14
linuxlinux_kernel>= 6.14.2 < 6.14.76.14.7
linuxlinux_kernel>= 6.6.87 < 6.6.916.6.91
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.