CVE-2025-39929
HIGH severity · CVSS 7.5 · CWE-401
7.5CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path During tests of another unrelated patch I was able to trigger this error: Objects remaining on __kmem_cache_shutdown()
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactNone
Integrity impactNone
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/0991418bf98f191d0c320bd25245fcffa1998c7e ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/0991418bf98f191d0c320bd25245fcffa1998c7ePatch
- https://git.kernel.org/stable/c/3d7c075c878ac844e33c43e506c2fa27ac7e9689Patch
- https://git.kernel.org/stable/c/922338efaad63cfe30d459dfc59f9d69ff93ded4Patch
- https://git.kernel.org/stable/c/daac51c7032036a0ca5f1aa419ad1b0471d1c6e0Patch
- https://git.kernel.org/stable/c/e7b7a93879558e77d950f1ff9a6f3daa385b33dfPatch
- https://git.kernel.org/stable/c/5aa69aabcb275a8012265233c7694076ce1d9102
- https://git.kernel.org/stable/c/aa4cf7615328eae44f3b4bf5f4fde3fb390c27c6
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html