CVE-2025-38437

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38437
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38437.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38437
Downstream
Related
Published
2025-07-25T15:27:16.995Z
Modified
2025-11-28T02:35:16.027542Z
Summary
ksmbd: fix potential use-after-free in oplock/lease break ack
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix potential use-after-free in oplock/lease break ack

If ksmbdiovpinrsp return error, use-after-free can happen by accessing opinfo->state and opinfoput and ksmbdfdput could called twice.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38437.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
e38ec88a2b42c494601b1213816d75f0b54d9bf0
Fixed
97c355989928a5f60b228ef5266c1be67a46cdf9
Fixed
815f1161d6dbc4c54ccf94b7d3fdeab34b4d7477
Fixed
8106adc21a2270c16abf69cd74ccd7c79c6e7acd
Fixed
50f930db22365738d9387c974416f38a06e8057e

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.1.146
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.99
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.39
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.7