CVE-2025-40285

Source
https://cve.org/CVERecord?id=CVE-2025-40285
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40285.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40285
Downstream
Related
Published
2025-12-06T21:51:09.590Z
Modified
2026-03-20T12:43:14.999726Z
Summary
smb/server: fix possible refcount leak in smb2_sess_setup()
Details

In the Linux kernel, the following vulnerability has been resolved:

smb/server: fix possible refcount leak in smb2sesssetup()

Reference count of ksmbdsession will leak when session need reconnect. Fix this by adding the missing ksmbdusersessionput().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40285.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
37a0e2b362b3150317fb6e2139de67b1e29ae5ff
Fixed
6fc935f798d44a8eb8a5e6659198399fbf57b981
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
450a844c045ff0895d41b05a1cbe8febd1acfcfd
Fixed
e671f9bb97805771380c98de944e2ceab6949188
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a39e31e22a535d47b14656a7d6a893c7f6cf758c
Fixed
dcc51dfe6ff26b52cac106865a172ac982d78401
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b95629435b84b9ecc0c765995204a4d8a913ed52
Fixed
d37b2c81c83d6c0d5ca582f4fe73c672983f9e0d
Fixed
379510a815cb2e64eb0a379cb62295d6ade65df0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
2107ab40629aeabbec369cf34b8cf0f288c3eb1b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40285.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.159
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.117
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.59
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40285.json"