cbcvebase.
CVE-2025-38191
published 2025-07-04

CVE-2025-38191: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->user is not set yet, It can pass the user argument as NULL to destroy_previous_session. sess->user will be set in ksmbd_krb5_authenticate(). So this patch move calling destroy_previous_session() after ksmbd_krb5_authenticate().

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 281afc52e2961cd5dd8326ebc9c5bc40904c0468281afc52e2961cd5dd8326ebc9c5bc40904c0468
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 0902625a24eea7fdc187faa5d97df244d159dd6e0902625a24eea7fdc187faa5d97df244d159dd6e
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 1193486dffb7432a09f57f5d09049b4d4123538b1193486dffb7432a09f57f5d09049b4d4123538b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 076f1adefb9837977af7ed233883842ddc446644076f1adefb9837977af7ed233883842ddc446644
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 7ac5b66acafcc9292fb935d7e03790f2b8b2dc0e7ac5b66acafcc9292fb935d7e03790f2b8b2dc0e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.15 < 6.1.1426.1.142
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.2 < 6.6.956.6.95
linuxlinux_kernel>= 6.7 < 6.12.356.12.35
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM