Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ksmbd_vfs_getattr() fails, the reference count of ksmbd_file must be released.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.6.32, < 6.6.124 |
References
- https://git.kernel.org/stable/c/2456fde2b137703328f1695f60c68fe488d17e36Patch
- https://git.kernel.org/stable/c/39ca11ff158c98fb092176f06047628c54bcf7a1Patch
- https://git.kernel.org/stable/c/4665e52bde3b1f8f442895ce7d88fa62a43e48c4Patch
- https://git.kernel.org/stable/c/f416c556997aa56ec4384c6b6efd6a0e6ac70aa7Patch
FAQ
What is CVE-2025-71223?
CVE-2025-71223 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ksmbd_vfs_getattr() fails, the reference count of ksmbd_file must be released.
How severe is CVE-2025-71223?
CVE-2025-71223 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71223?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.