CVE-2025-37899 describes a use-after-free vulnerability in the ksmbd module of the Linux kernel, affecting various Linux kernel versions. This flaw, rated High severity with a CVSS score of 7.8, allows a local, low-privileged attacker to achieve high confidentiality, integrity, and availability impacts without user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.15, < 6.12.28CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.14.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* | ||
6.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:* | ||
6.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 24, 2026USN-8059-9: Linux kernel (Azure FIPS) vulnerabilities
Mar 24, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 10, 2026Linux kernel (AWS FIPS) vulnerabilities
Mar 4, 2026Linux kernel vulnerabilities
Feb 26, 2026Linux kernel (FIPS) vulnerabilities
Feb 25, 2026Linux kernel (Real-time) vulnerabilities
Feb 25, 2026Linux kernel vulnerabilities
Feb 25, 2026Linux kernel (Raspberry Pi Real-time) vulnerabilities
Feb 24, 2026Linux kernel vulnerabilities
Feb 24, 2026kernel: ksmbd: fix use-after-free in session logoff
May 20, 2025ksmbd: fix use-after-free in session logoff
May 13, 2025