cbcvebase.
CVE-2025-38325
published 2025-07-10

CVE-2025-38325: In the Linux kernel, the following vulnerability has been resolved: ksmbd: add free_transport ops in ksmbd connection free_transport function for tcp…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.39%
31.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add free_transport ops in ksmbd connection free_transport function for tcp connection can be called from smbdirect. It will cause kernel oops. This patch add free_transport ops in ksmbd connection, and add each free_transports for tcp and smbdirect.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 1aec4d14cf81b7b3e7b69eb1cfa94144eed7138e < 3890da762a66191c440b0bd6e3ee45501edbb0c13890da762a66191c440b0bd6e3ee45501edbb0c1
linuxlinux>= 1da8bd9a10ecd718692732294d15fd801c0eabb5 < 52f5a52dc17a4a7b4363ac03fe2c4ef26f020dc652f5a52dc17a4a7b4363ac03fe2c4ef26f020dc6
linuxlinux>= 21a4e47578d44c6b37c4fc4aba8ed7cc8dbb13de < 3f3aae77280aad9f5acc6709c596148966f765c73f3aae77280aad9f5acc6709c596148966f765c7
linuxlinux>= 21a4e47578d44c6b37c4fc4aba8ed7cc8dbb13de < a89f5fae998bdc4d0505306f93844c9ae059d50ca89f5fae998bdc4d0505306f93844c9ae059d50c
linuxlinux>= 6.12.26 < 6.12.356.12.35
linuxlinux>= 6.14.4 < 6.156.15
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 6.12.26 < 6.12.356.12.35
linuxlinux_kernel>= 6.14.4 < 6.156.15
linuxlinux_kernel>= 6.15.1 < 6.15.46.15.4
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_msrc7.5HIGH
vendor_ubuntu5.6MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.