In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix Preauh_HashValue race condition
If client send multiple session setup requests to ksmbd, PreauhHashValue race condition could happen. There is no need to free sess->PreauhHashValue at session setup phase. It can be freed together with session at connection termination phase.
[
{
"digest": {
"length": 5355.0,
"function_hash": "141749231558801172115546232139565089353"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b69fd87076daa66f3d186bd421a7b0ee0cb45829",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-07827495",
"signature_type": "Function",
"target": {
"file": "fs/smb/server/smb2pdu.c",
"function": "smb2_sess_setup"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"119503211405839148911742203737027705086",
"245274284282518017066210542996035553948",
"120610461928015751830355172687609427332",
"102595495521943856499385416313050555838",
"85588084354505722632905249094536309499",
"48945596071727820898456304356908243045",
"225636643417979065393269825784553769669",
"180932088894087758928990636869391276569",
"82677515786533971569571141939042289534",
"91241543591994024896655853896771191454"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6613887da1d18dd2ecfd6c6148a873c4d903ebdc",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-31b8c8d4",
"signature_type": "Line",
"target": {
"file": "fs/smb/server/smb2pdu.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"119503211405839148911742203737027705086",
"245274284282518017066210542996035553948",
"120610461928015751830355172687609427332",
"102595495521943856499385416313050555838",
"85588084354505722632905249094536309499",
"48945596071727820898456304356908243045",
"225636643417979065393269825784553769669",
"180932088894087758928990636869391276569",
"82677515786533971569571141939042289534",
"91241543591994024896655853896771191454"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b69fd87076daa66f3d186bd421a7b0ee0cb45829",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-489eddd3",
"signature_type": "Line",
"target": {
"file": "fs/smb/server/smb2pdu.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"119503211405839148911742203737027705086",
"245274284282518017066210542996035553948",
"120610461928015751830355172687609427332",
"102595495521943856499385416313050555838",
"85588084354505722632905249094536309499",
"48945596071727820898456304356908243045",
"225636643417979065393269825784553769669",
"180932088894087758928990636869391276569",
"82677515786533971569571141939042289534",
"91241543591994024896655853896771191454"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7d7c0c5304c88bcbd7a85e9bcd61d27e998ba5fc",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-4bc10895",
"signature_type": "Line",
"target": {
"file": "fs/smb/server/smb2pdu.c"
}
},
{
"digest": {
"length": 5453.0,
"function_hash": "274552647367337991290355050403618815949"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7d7c0c5304c88bcbd7a85e9bcd61d27e998ba5fc",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-5612544a",
"signature_type": "Function",
"target": {
"file": "fs/smb/server/smb2pdu.c",
"function": "smb2_sess_setup"
}
},
{
"digest": {
"length": 5355.0,
"function_hash": "141749231558801172115546232139565089353"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fbf5c0845ed15122a770bca9be1d9b60b470d3aa",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-70a4165d",
"signature_type": "Function",
"target": {
"file": "fs/smb/server/smb2pdu.c",
"function": "smb2_sess_setup"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"119503211405839148911742203737027705086",
"245274284282518017066210542996035553948",
"120610461928015751830355172687609427332",
"102595495521943856499385416313050555838",
"85588084354505722632905249094536309499",
"48945596071727820898456304356908243045",
"225636643417979065393269825784553769669",
"180932088894087758928990636869391276569",
"82677515786533971569571141939042289534",
"91241543591994024896655853896771191454"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fbf5c0845ed15122a770bca9be1d9b60b470d3aa",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-85eb9f6f",
"signature_type": "Line",
"target": {
"file": "fs/smb/server/smb2pdu.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"119503211405839148911742203737027705086",
"245274284282518017066210542996035553948",
"120610461928015751830355172687609427332",
"102595495521943856499385416313050555838",
"85588084354505722632905249094536309499",
"48945596071727820898456304356908243045",
"225636643417979065393269825784553769669",
"180932088894087758928990636869391276569",
"82677515786533971569571141939042289534",
"91241543591994024896655853896771191454"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@44a3059c4c8cc635a1fb2afd692d0730ca1ba4b6",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-8e7261b1",
"signature_type": "Line",
"target": {
"file": "fs/smb/server/smb2pdu.c"
}
},
{
"digest": {
"length": 5452.0,
"function_hash": "319391757451134682613957270334932009841"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@edeecc7871e8fc0878d53ce286c75040a0e38f6c",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-bd8a99c6",
"signature_type": "Function",
"target": {
"file": "fs/smb/server/smb2pdu.c",
"function": "smb2_sess_setup"
}
},
{
"digest": {
"length": 5453.0,
"function_hash": "274552647367337991290355050403618815949"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@44a3059c4c8cc635a1fb2afd692d0730ca1ba4b6",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-c445fe24",
"signature_type": "Function",
"target": {
"file": "fs/smb/server/smb2pdu.c",
"function": "smb2_sess_setup"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"119503211405839148911742203737027705086",
"245274284282518017066210542996035553948",
"120610461928015751830355172687609427332",
"102595495521943856499385416313050555838",
"85588084354505722632905249094536309499",
"48945596071727820898456304356908243045",
"225636643417979065393269825784553769669",
"180932088894087758928990636869391276569",
"82677515786533971569571141939042289534",
"91241543591994024896655853896771191454"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@edeecc7871e8fc0878d53ce286c75040a0e38f6c",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-decdbb0a",
"signature_type": "Line",
"target": {
"file": "fs/smb/server/smb2pdu.c"
}
},
{
"digest": {
"length": 5453.0,
"function_hash": "274552647367337991290355050403618815949"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6613887da1d18dd2ecfd6c6148a873c4d903ebdc",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2025-38561-e671a110",
"signature_type": "Function",
"target": {
"file": "fs/smb/server/smb2pdu.c",
"function": "smb2_sess_setup"
}
}
]