cbcvebase.
CVE-2025-40286
published 2025-12-06

CVE-2025-40286: In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible memory leak in smb2_read() Memory leak occurs when…

PriorityP417high7.8
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible memory leak in smb2_read() Memory leak occurs when ksmbd_vfs_read() fails. Fix this by adding the missing kvfree().

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 0797c6cf3b857cc229ab2bc69552938dcd738d780797c6cf3b857cc229ab2bc69552938dcd738d78
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 63d8706a2c09a0c29b8b0e8a44bc7a1339685de963d8706a2c09a0c29b8b0e8a44bc7a1339685de9
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < f1305587731886da37a214cda812ade246c653b0f1305587731886da37a214cda812ade246c653b0
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < bfda5422a16651d0bf864ec468b1c216e1b10d91bfda5422a16651d0bf864ec468b1c216e1b10d91
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 6fced056d2cc8d01b326e6fcfabaacb9850b71a46fced056d2cc8d01b326e6fcfabaacb9850b71a4
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.9-16.17.9-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.15.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.96.17.9
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.596.12.59
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.