Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use read lock to protect whole loop.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.15, < 6.6.88 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/18b4fac5ef17f77fed9417d22210ceafd6525fc7Patch
- https://git.kernel.org/stable/c/296cb5457cc6f4a754c4ae29855f8a253d52bcc6Patch
- https://git.kernel.org/stable/c/d54ab1520d43e95f9b2e22d7a05fc9614192e5a5Patch
- https://git.kernel.org/stable/c/d73686367ad68534257cd88a36ca3c52cb8b81d8Patch
FAQ
What is CVE-2025-37776?
CVE-2025-37776 is a vulnerability with a CVSS score of 7.0 (HIGH). In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues...
How severe is CVE-2025-37776?
CVE-2025-37776 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-37776?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.