We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-37952

ksmbd: Fix UAF in __close_file_table_ids



Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file via __ksmbd_close_fd while another thread holds a reference to it. The existing checks on fp->refcount are not sufficient to prevent this. The fix takes ft->lock around the section which removes the file from the file table. This prevents two threads acquiring the same file pointer via __close_file_table_ids, as well as the other functions which retrieve a file from the IDR and which already use this same lock.

Reserved 2025-04-16 | Published 2025-05-20 | Updated 2025-05-26 | Assigner Linux

Product status

Default status
unaffected

0626e6641f6b467447c81dd7678a69c66f7746cf before fec1f9e9a650e8e7011330a085c77e7bf2a08ea9
affected

0626e6641f6b467447c81dd7678a69c66f7746cf before 9e9841e232b51171ddf3bc4ee517d5d28dc8cad6
affected

0626e6641f6b467447c81dd7678a69c66f7746cf before 16727e442568a46d9cca69fe2595896de86e120d
affected

0626e6641f6b467447c81dd7678a69c66f7746cf before 36991c1ccde2d5a521577c448ffe07fcccfe104d
affected

Default status
affected

5.15
affected

Any version before 5.15
unaffected

6.6.91
unaffected

6.12.29
unaffected

6.14.7
unaffected

6.15
unaffected

References

git.kernel.org/...c/fec1f9e9a650e8e7011330a085c77e7bf2a08ea9

git.kernel.org/...c/9e9841e232b51171ddf3bc4ee517d5d28dc8cad6

git.kernel.org/...c/16727e442568a46d9cca69fe2595896de86e120d

git.kernel.org/...c/36991c1ccde2d5a521577c448ffe07fcccfe104d

cve.org (CVE-2025-37952)

nvd.nist.gov (CVE-2025-37952)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-37952

Support options

Helpdesk Chat, Email, Knowledgebase