CVE-2025-68246 — Linux vulnerability
33 documents7 sources
Severity
3.2LOWOSV
No vectorEPSS
0.1%
top 84.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: close accepted socket when per-IP limit rejects connection
When the per-IP connection limit is exceeded in ksmbd_kthread_fn(),
the code sets ret = -EAGAIN and continues the accept loop without
closing the just-accepted socket. That leaks one socket per rejected
attempt from a single IP and enables a trivial remote DoS.
Release client_sk before continuing.
This bug was found with ZeroPath.
Affected Packages6 packages
▶CVEListV5linux/linux0626e6641f6b467447c81dd7678a69c66f7746cf — 7a3c7154d5fc05956a8ad9e72ecf49e21555bfca+5