CVE-2025-21955
HIGH severity · CVSS 8.8
8.8CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock break notification ksmbd_work could be freed when after connection release. Increment r_count of ksmbd_conn to indicate that requests are not finished yet and to not release the connection.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/09aeab68033161cb54f194da93e51a11aee6144b ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/09aeab68033161cb54f194da93e51a11aee6144bPatch
- https://git.kernel.org/stable/c/3aa660c059240e0c795217182cf7df32909dd917Patch
- https://git.kernel.org/stable/c/a4261bbc33fbf99b99c80aa3a2c5097611802980Patch
- https://git.kernel.org/stable/c/f17d1c63a76b0fe8e9c78023a86507a3a6d62cfaPatch