In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix session use-after-free in multichannel connection
There is a race condition between session setup and
ksmbd_sessions_deregister. The session can be freed before the connection
is added to channel list of session.
This patch check reference count of session before freeing it.
CVSS
No CVSS.
References
Configurations
Configuration 1 (hide)
|
History
25 Apr 2025, 18:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://git.kernel.org/stable/c/3980770cb1470054e6400fd97668665975726737 - Patch | |
References | () https://git.kernel.org/stable/c/9069939d762138e232a6f79e3e1462682ed6a17d - Patch | |
References | () https://git.kernel.org/stable/c/7dfbd4c43eed91dd2548a95236908025707a8dfd - Patch | |
References | () https://git.kernel.org/stable/c/596407adb9af1ee75fe7c7529607783d31b66e7f - Patch | |
References | () https://git.kernel.org/stable/c/94c281721d4ed2d972232414b91d98a6f5bdb16b - Patch | |
References | () https://git.kernel.org/stable/c/fa4cdb8cbca7d6cb6aa13e4d8d83d1103f6345db - Patch | |
First Time |
Linux linux Kernel
Linux |
|
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
16 Apr 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-16 15:15
Updated : 2025-04-25 18:42
NVD link : CVE-2025-22040
Mitre link : CVE-2025-22040
JSON object : View
Products Affected
linux
- linux_kernel
CWE
No CWE.