CVE-2025-39720 is a refcount leak vulnerability in the Linux kernel's ksmbd module, specifically affecting the linux_kernel product. This flaw prevents proper memory deallocation when ksmbd_conn_releasing returns true, leading to resource exhaustion. Rated Medium (CVSS 5.5), it requires local access with low attack complexity and can cause high availability impact. There is currently no public exploit code available, it is not listed in KEV, and while it has garnered some community discussion and media coverage, it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.15, < 6.6.103CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.16.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:* | ||
6.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026ksmbd: fix refcount leak causing resource not released
Sep 9, 2025kernel: ksmbd: fix refcount leak causing resource not released
Sep 5, 2025