CVE-2025-38527 is a high-severity use-after-free vulnerability in the Linux kernel's SMB client, specifically affecting the cifs_oplock_break() function. This race condition can lead to system instability and potential privilege escalation on Debian and other Linux distributions utilizing the affected kernel versions. With a CVSS score of 7.8 (HIGH), successful exploitation could result in high confidentiality, integrity, and availability impacts, requiring local access and low privileges. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.16.72, < 3.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.9.171, < 4.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.14.114, < 4.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.19.37, < 4.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.0.10, < 5.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026kernel: smb: client: fix use-after-free in cifs_oplock_break
Aug 16, 2025smb: client: fix use-after-free in cifs_oplock_break
Aug 12, 2025