NA
CVSSv3

CVE-2025-37899

CVSSv4: NA | CVSSv3: NA | CVSSv2: NA | VMScore: NA | EPSS: 0.00012 | KEV: Not Included
Published: 20/05/2025 Updated: 24/05/2025

Vulnerability Summary

Linux Kernel Use-After-Free Vulnerability in ksmbd SMB Server Session Handling

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the session being free'd. The handler for that connection could be in the smb2_sess_setup function which makes use of sess->user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux

linux linux kernel

Github Repositories

Vulnerabilidad Use-After-Free en ksmbd del Kernel de Linux (CVE-2025-37899) Descripción Se ha descubierto una vulnerabilidad de tipo use-after-free en el módulo ksmbd del kernel de Linux, responsable de la implementación del protocolo SMB (Server Message Block) para el intercambio de archivos en red Esta vulnerabilidad, identificada como CVE-2025-37899, po

Artefacts for blog post on finding CVE-2025-37899 with o3

This is the artefact repository associated with my blog post How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation See that post for details

IT-News-Mai-2025 Quantencomputer Verschlüsselung wwwcsoonlinecom/article/3995867/quantencomputer-knacken-rsa-verschlusselungen-noch-schnellerhtml wwwcsoonlinecom/article/3995036/breaking-rsa-encryption-just-got-20x-easier-for-quantum-computershtml wwwtechradarcom/pro/security/windows-11-is-getting-top-level-protection-against-the-next-genera