CVE-2025-68817

Source
https://cve.org/CVERecord?id=CVE-2025-68817
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68817.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68817
Downstream
Published
2026-01-13T15:29:21.210Z
Modified
2026-05-07T04:17:34.255870Z
Summary
ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in ksmbdtreeconnect_put under concurrency

Under high concurrency, A tree-connection object (tcon) is freed on a disconnect path while another path still holds a reference and later executes *_put()/write on it.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68817.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dd45db4d9bbc8f122a9b4db5ce94ae29fcf03d3c
Fixed
446beed646b2e426dd53d27358365f8678e1dd01
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7b58ee8d0b91359554cf219cd4f33872ea2afd66
Fixed
d092de8a26c952379ded8e6b0bda31d89befac1a
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
33b235a6e6ebe0f05f3586a71e8d281d00f71e2e
Fixed
d64977495e44855f2b28d8ce56107c963a7a50e4
Fixed
21a3d01fc6db5129f81edb0ab7cb94fd758bcbea
Fixed
063cbbc6f595ea36ad146e1b7d2af820894beb21
Fixed
b39a1833cc4a2755b02603eec3a71a85e9dff926

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68817.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.199
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68817.json"