CVE-2025-38561

MEDIUM EPSS 30.9%
Published Aug 19, 202510mo ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Medium
Find Similar
Published Aug 19, 2025 10mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If client send multiple session setup requests to ksmbd, Preauh_HashValue race condition could happen. There is no need to free sess->Preauh_HashValue at session setup phase. It can be freed together with session at connection termination phase.

CVSS Details

Base Score
4.7
Exploitability
1.0
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
30.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-362

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥5.15  –  <6.1.148
linuxlinux_kernel*≥6.2  –  <6.6.102
linuxlinux_kernel*≥6.7  –  <6.12.42
linuxlinux_kernel*≥6.13  –  <6.15.10
linuxlinux_kernel*≥6.16  –  <6.16.1
debiandebian_linux11.0any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/44a3059c4c8cc635a1fb2afd692d0730ca1ba4b6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6613887da1d18dd2ecfd6c6148a873c4d903ebdc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d7c0c5304c88bcbd7a85e9bcd61d27e998ba5fc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b69fd87076daa66f3d186bd421a7b0ee0cb45829
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/edeecc7871e8fc0878d53ce286c75040a0e38f6c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fbf5c0845ed15122a770bca9be1d9b60b470d3aa
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory
  • zerodayinitiative.com https://www.zerodayinitiative.com/advisories/ZDI-25-916/
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/44a3059c4c8cc635a1fb2afd692d0730ca1ba4b6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6613887da1d18dd2ecfd6c6148a873c4d903ebdc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d7c0c5304c88bcbd7a85e9bcd61d27e998ba5fc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b69fd87076daa66f3d186bd421a7b0ee0cb45829
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/edeecc7871e8fc0878d53ce286c75040a0e38f6c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fbf5c0845ed15122a770bca9be1d9b60b470d3aa
    Patch