CVE-2025-40328 addresses a use-after-free (UAF) vulnerability in the Linux kernel's SMB client, specifically within the smb2_close_cached_fid() function. This flaw could occur due to a race condition where a new reference was acquired after the reference count dropped to zero but before a necessary lock was obtained. The vulnerability has a low FAUCET Risk Score of 7/100 and an extremely low EPSS score, indicating a very low probability of exploitation. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.1CNA affecteddefault affected | |
| Linux | Linux | >= ebe98f1447bbccf8228335c62d86af02a0ed23f7, < 065bd62412271a2d734810dd50336cae88c54427, >= ebe98f1447bbccf8228335c62d86af02a0ed23f7, < 734e99623c5b65bf2c03e35978a0b980ebc3c2f8, >= ebe98f1447bbccf8228335c62d86af02a0ed23f7, < bdb596ceb4b7c3f28786a33840263728217fbcf5, >= ebe98f1447bbccf8228335c62d86af02a0ed23f7, < cb52d9c86d70298de0ab7c7953653898cbc0efd6CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel (Azure) vulnerabilities
Feb 24, 2026smb: client: fix potential UAF in smb2_close_cached_fid()
Dec 9, 2025kernel: smb: client: fix potential UAF in smb2_close_cached_fid()
Dec 9, 2025