CVE-2025-40103

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-40103
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40103.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40103
Downstream
Related
Published
2025-10-30T09:48:08.421Z
Modified
2025-11-28T02:34:39.844116Z
Summary
smb: client: Fix refcount leak for cifs_sb_tlink
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: Fix refcount leak for cifssbtlink

Fix three refcount inconsistency issues related to cifs_sb_tlink.

Comments for cifs_sb_tlink state that cifs_put_tlink() needs to be called after successful calls to cifs_sb_tlink(). Three calls fail to update refcount accordingly, leading to possible resource leaks.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40103.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8ceb984379462f94bdebef3288d569c6e1f912ea
Fixed
790282abe9d805f08618c1c24ea2529e7259b692
Fixed
d7dd034c14928306db1b46be277ae439b84dacf9
Fixed
e15605b68b490186da2ad8029c0351a9cfb0b9af
Fixed
896bb31e1416f582503db1350cf1bd10dc64e5a6
Fixed
c2b77f42205ef485a647f62082c442c1cd69d3fc

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40103.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
6.1.158
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.114
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.55
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.5

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40103.json"