cbcvebase.
CVE-2025-40285
published 2025-12-06

CVE-2025-40285: In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of…

PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.40%
33.3th percentile
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 37a0e2b362b3150317fb6e2139de67b1e29ae5ff < 6fc935f798d44a8eb8a5e6659198399fbf57b9816fc935f798d44a8eb8a5e6659198399fbf57b981
linuxlinux>= 450a844c045ff0895d41b05a1cbe8febd1acfcfd < e671f9bb97805771380c98de944e2ceab6949188e671f9bb97805771380c98de944e2ceab6949188
linuxlinux>= 5.15.176 < 5.165.16
linuxlinux>= 6.1.121 < 6.1.1596.1.159
linuxlinux>= 6.12.6 < 6.12.596.12.59
linuxlinux>= 6.6.67 < 6.6.1176.6.117
linuxlinux>= a39e31e22a535d47b14656a7d6a893c7f6cf758c < dcc51dfe6ff26b52cac106865a172ac982d78401dcc51dfe6ff26b52cac106865a172ac982d78401
linuxlinux>= b95629435b84b9ecc0c765995204a4d8a913ed52 < d37b2c81c83d6c0d5ca582f4fe73c672983f9e0dd37b2c81c83d6c0d5ca582f4fe73c672983f9e0d
linuxlinux>= b95629435b84b9ecc0c765995204a4d8a913ed52 < 379510a815cb2e64eb0a379cb62295d6ade65df0379510a815cb2e64eb0a379cb62295d6ade65df0
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.9-16.17.9-1
linuxlinux_kernel>= 0 < 6.1.1596.1.159
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.13.0 < 6.17.96.17.9
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.596.12.59
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.