CVE-2025-68226
published 2025-12-16CVE-2025-68226: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix incomplete backport in cfids_invalidation_worker() The previous commit…
PriorityP341high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.30%
22.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in
smb2_close_cached_fid()") was an incomplete backport and missed one
kref_put() call in cfids_invalidation_worker() that should have been
converted to close_cached_dir().
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.17.10-1 (forky) | linux 6.17.10-1 (forky) |
| linux | linux | >= 6.17.8 < 6.17.10 | 6.17.10 |
| linux | linux | >= bdb596ceb4b7c3f28786a33840263728217fbcf5 < abd29b6e17a918fdd68352ce4813e167acc8727e | abd29b6e17a918fdd68352ce4813e167acc8727e |
| linux | linux_kernel | >= 0 < 6.17.10-1 | 6.17.10-1 |
| linux | linux_kernel | >= 6.17.8 < 6.17.10 | 6.17.10 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqrv-x663-5498: In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous
ghsa_unreviewed·2025-12-16
CVE-2025-68226 GHSA-gqrv-x663-5498: In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in
smb2_close_cached_fid()") was an incomplete backport and missed one
kref_put() call in cfids_invalidation_worker() that should have been
converted to close_cached_dir().
OSV
smb: client: fix incomplete backport in cfids_invalidation_worker()
osv·2025-12-16
CVE-2025-68226 smb: client: fix incomplete backport in cfids_invalidation_worker()
smb: client: fix incomplete backport in cfids_invalidation_worker()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in
smb2_close_cached_fid()") was an incomplete backport and missed one
kref_put() call in cfids_invalidation_worker() that should have been
converted to close_cached_dir().
OSV
CVE-2025-68226: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix incomplete backport in cfids_invalidation_worker() The previous c
osv·2025-12-16
CVE-2025-68226 CVE-2025-68226: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix incomplete backport in cfids_invalidation_worker() The previous c
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix incomplete backport in cfids_invalidation_worker() The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in smb2_close_cached_fid()") was an incomplete backport and missed one kref_put() call in cfids_invalidation_worker() that should have been converted to close_cached_dir().
Red Hat
kernel: Linux kernel SMB client: Denial of Service due to Use-After-Free
vendor_redhat·2025-12-16·CVSS 5.5
CVE-2025-68226 [MEDIUM] CWE-911 kernel: Linux kernel SMB client: Denial of Service due to Use-After-Free
kernel: Linux kernel SMB client: Denial of Service due to Use-After-Free
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in
smb2_close_cached_fid()") was an incomplete backport and missed one
kref_put() call in cfids_invalidation_worker() that should have been
converted to close_cached_dir().
A flaw was found in the Linux kernel’s SMB client implementation (fs/smb/client/cached_dir.c). An earlier commit intended to fix a potential use-after-free in smb2_close_cached_fid() was incompletely backported, resulting in a missing kref_put() call in the cfids_invalidation_worker() function. Under certain conditions, this can lead to a use-after
Debian
CVE-2025-68226: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
vendor_debian·2025
CVE-2025-68226 [LOW] CVE-2025-68226: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix incomplete backport in cfids_invalidation_worker() The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in smb2_close_cached_fid()") was an incomplete backport and missed one kref_put() call in cfids_invalidation_worker() that should have been converted to close_cached_dir().
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.17.10-1)
sid: resolved (fixed in 6.17.10-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-68226 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68226 CVE-2025-68226 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68226 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in
smb2_close_cached_fid()") was an incomplete backport and missed one
kref_put() call in cfids_invalidation_worker() that should have been
converted to close_cached_dir().
Source : NVD
Published December 16, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel6.12-tools-debugin
Bugzilla
CVE-2025-68226 kernel: Linux kernel SMB client: Denial of Service due to Use-After-Free
bugzilla·2025-12-16
CVE-2025-68226 [MEDIUM] CVE-2025-68226 kernel: Linux kernel SMB client: Denial of Service due to Use-After-Free
CVE-2025-68226 kernel: Linux kernel SMB client: Denial of Service due to Use-After-Free
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfids_invalidation_worker()
The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in
smb2_close_cached_fid()") was an incomplete backport and missed one
kref_put() call in cfids_invalidation_worker() that should have been
converted to close_cached_dir().
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025121635-CVE-2025-68226-6559@gregkh/T
2025-12-16
Published