VulnerabilityAnalyzed
CVE-2025-71223
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ksmbd_vfs_getattr() fails, the reference count of ksmbd_file must be released.
MEDIUM 5.5EPSS 0.12%
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ksmbd_vfs_getattr() fails, the reference count of ksmbd_file must be released.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/2456fde2b137703328f1695f60c68fe488d17e36Patch
- https://git.kernel.org/stable/c/39ca11ff158c98fb092176f06047628c54bcf7a1Patch
- https://git.kernel.org/stable/c/4665e52bde3b1f8f442895ce7d88fa62a43e48c4Patch
- https://git.kernel.org/stable/c/f416c556997aa56ec4384c6b6efd6a0e6ac70aa7Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.