cbcvebase.
CVE-2025-71220
published 2026-02-14

CVE-2025-71220: In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error path in create_smb2_pipe() When…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error path in create_smb2_pipe() When ksmbd_iov_pin_rsp() fails, we should call ksmbd_session_rpc_close().

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 5.15.145 < 5.15.2005.15.200
linuxlinux>= 6.1.71 < 6.1.1636.1.163
linuxlinux>= 9f297df20d93411c0b4ddad7f88ba04a7cd36e77 < 2b7b4df87fe6f2db6ee45f475de6b37b8b8e5d292b7b4df87fe6f2db6ee45f475de6b37b8b8e5d29
linuxlinux>= e2b76ab8b5c9327ab2dae6da05d0752eb2f4771d < 04dd114b682a4ccaeba2c2bad049c8b50ce740d804dd114b682a4ccaeba2c2bad049c8b50ce740d8
linuxlinux>= e2b76ab8b5c9327ab2dae6da05d0752eb2f4771d < ac18761b530b5dd40f59af8a25902282e5512854ac18761b530b5dd40f59af8a25902282e5512854
linuxlinux>= e2b76ab8b5c9327ab2dae6da05d0752eb2f4771d < fdda836fcee6fdbcccc24e3679097efb583f581ffdda836fcee6fdbcccc24e3679097efb583f581f
linuxlinux>= e2b76ab8b5c9327ab2dae6da05d0752eb2f4771d < 7c28f8eef5ac5312794d8a52918076dcd787e53b7c28f8eef5ac5312794d8a52918076dcd787e53b
linuxlinux>= f2283680a80571ca82d710bc6ecd8f8beac67d63 < a2c68e256fb7a4ac34154c6e865a1389acca839fa2c68e256fb7a4ac34154c6e865a1389acca839f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 5.15.145 < 5.15.2005.15.200
linuxlinux_kernel>= 6.1.71 < 6.1.1636.1.163
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.6 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.