cbcvebase.
CVE-2025-68226
published 2025-12-16

CVE-2025-68226: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix incomplete backport in cfids_invalidation_worker() The previous commit…

PriorityP341high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.30%
22.3th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix incomplete backport in cfids_invalidation_worker() The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in smb2_close_cached_fid()") was an incomplete backport and missed one kref_put() call in cfids_invalidation_worker() that should have been converted to close_cached_dir().

Affected

5 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.10-1 (forky)linux 6.17.10-1 (forky)
linuxlinux>= 6.17.8 < 6.17.106.17.10
linuxlinux>= bdb596ceb4b7c3f28786a33840263728217fbcf5 < abd29b6e17a918fdd68352ce4813e167acc8727eabd29b6e17a918fdd68352ce4813e167acc8727e
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 6.17.8 < 6.17.106.17.10

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.