cbcvebase.
CVE-2025-71150
published 2026-01-23

CVE-2025-71150: In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is found on session lookup When a session is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is found on session lookup When a session is found but its state is not SMB2_SESSION_VALID, It indicates that no valid session was found, but it is missing to decrement the reference count acquired by the session lookup, which results in a reference count leak. This patch fixes the issue by explicitly calling ksmbd_user_session_put to release the reference to the session.

Affected

74 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 2107ab40629aeabbec369cf34b8cf0f288c3eb1b < 11fe566b442e3bc2774191740fd377739a87a1c011fe566b442e3bc2774191740fd377739a87a1c0
linuxlinux>= 37a0e2b362b3150317fb6e2139de67b1e29ae5ff < 0fb87b28cafae71e9c8248432cc3a6a1fd759efc0fb87b28cafae71e9c8248432cc3a6a1fd759efc
linuxlinux>= 450a844c045ff0895d41b05a1cbe8febd1acfcfd < e54fb2a4772545701766cba08aab20de5eace8cde54fb2a4772545701766cba08aab20de5eace8cd
linuxlinux>= 5.15.176 < 5.15.2035.15.203
linuxlinux>= 6.1.121 < 6.1.1606.1.160
linuxlinux>= 6.12.6 < 6.12.646.12.64
linuxlinux>= 6.6.67 < 6.6.1206.6.120
linuxlinux>= a39e31e22a535d47b14656a7d6a893c7f6cf758c < 02e06785e85b4bd86ef3d23b7c8d87acc76773d502e06785e85b4bd86ef3d23b7c8d87acc76773d5
linuxlinux>= b95629435b84b9ecc0c765995204a4d8a913ed52 < 8cabcb4dd3dc85dd83a37d26efcc59a66a4074d78cabcb4dd3dc85dd83a37d26efcc59a66a4074d7
linuxlinux>= b95629435b84b9ecc0c765995204a4d8a913ed52 < cafb57f7bdd57abba87725eb4e82bbdca4959644cafb57f7bdd57abba87725eb4e82bbdca4959644
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 5.15.176 < 5.165.16
linuxlinux_kernel>= 6.1.121 < 6.1.1606.1.160

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.