VulnerabilityModified
CVE-2025-21955
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock break notification ksmbd_work could be freed when after connection release.
MEDIUM 5.5EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock break notification ksmbd_work could be freed when after connection release. Increment r_count of ksmbd_conn to indicate that requests are not finished yet and to not release the connection.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/09aeab68033161cb54f194da93e51a11aee6144bPatch
- https://git.kernel.org/stable/c/3aa660c059240e0c795217182cf7df32909dd917Patch
- https://git.kernel.org/stable/c/a4261bbc33fbf99b99c80aa3a2c5097611802980Patch
- https://git.kernel.org/stable/c/f17d1c63a76b0fe8e9c78023a86507a3a6d62cfaPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.