CVE-2025-37776
HIGH severity · CVSS 8.8 · Use-after-free
8.8CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use read lock to protect whole loop.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/18b4fac5ef17f77fed9417d22210ceafd6525fc7 ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/18b4fac5ef17f77fed9417d22210ceafd6525fc7Patch
- https://git.kernel.org/stable/c/296cb5457cc6f4a754c4ae29855f8a253d52bcc6Patch
- https://git.kernel.org/stable/c/d54ab1520d43e95f9b2e22d7a05fc9614192e5a5Patch
- https://git.kernel.org/stable/c/d73686367ad68534257cd88a36ca3c52cb8b81d8Patch