CVE-2025-37926

Source
https://cve.org/CVERecord?id=CVE-2025-37926
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37926.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37926
Downstream
Published
2025-05-20T15:21:53.359Z
Modified
2026-06-18T03:57:28.298634744Z
Summary
ksmbd: fix use-after-free in ksmbd_session_rpc_open
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in ksmbdsessionrpc_open

A UAF issue can occur due to a race condition between ksmbdsessionrpc_open() and _sessionrpcclose(). Add rpclock to the session to protect it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37926.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
a4348710a7267705b75692dc1a000920481d1d92
Fixed
1067361a1cc6ad9cdf7acfc47f90012b72ad1502
Fixed
8fb3b6c85b7e3127161623586b62abcc366caa20
Fixed
6323fec65fe54b365961fed260dd579191e46121
Fixed
a1f46c99d9ea411f9bf30025b912d881d36fc709

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37926.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.1.162
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.122
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.28
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37926.json"