CVE-2025-37962
Estado: AnalizadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix memory leak in parse_lease_state()
The previous patch that added bounds check for create lease context introduced a memory leak. When the bounds check fails, the function returns NULL without freeing the previously allocated lease_ctx_info structure.
This patch fixes the issue by adding kfree(lreq) before returning NULL in both boundary check cases.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-401
Referencias
- https://git.kernel.org/stable/c/2148d34371b06dac696c0497a98a6bf905a51650
- https://git.kernel.org/stable/c/829e19ef741d9e9932abdc3bee5466195e0852cf
- https://git.kernel.org/stable/c/af9e2d4732a548db8f6f5a90c2c20a789a3d7240
- https://git.kernel.org/stable/c/eb4447bcce915b43b691123118893fca4f372a8f
- https://git.kernel.org/stable/c/facf22c1a394c1e023dab5daf9a494f722771e1c
- https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-37962",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "629dd37acc336ad778979361c351e782053ea284",
"lessThan": "facf22c1a394c1e023dab5daf9a494f722771e1c",
"versionType": "git"
},
{
"status": "affected",
"version": "60b7207893a8a06c78441934931a08fdad63f18e",
"lessThan": "af9e2d4732a548db8f6f5a90c2c20a789a3d7240",
"versionType": "git"
},
{
"status": "affected",
"version": "800c482c9ef5910f05e3a713943c67cc6c1d4939",
"lessThan": "2148d34371b06dac696c0497a98a6bf905a51650",
"versionType": "git"
},
{
"status": "affected",
"version": "9a1b6ea955e6c7b29939a6d98701202f9d9644ec",
"lessThan": "829e19ef741d9e9932abdc3bee5466195e0852cf",
"versionType": "git"
},
{
"status": "affected",
"version": "bab703ed8472aa9d109c5f8c1863921533363dae",
"lessThan": "eb4447bcce915b43b691123118893fca4f372a8f",
"versionType": "git"
},
{
"status": "affected",
"version": "a41cd52f00907a040ca22c73d4805bb79b0d0972",
"versionType": "git"
},
{
"status": "affected",
"version": "6.13.11",
"lessThan": "6.14",
"versionType": "semver"
}
],
"programFiles": [
"fs/smb/server/oplock.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1.134",
"lessThan": "6.1.139",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.87",
"lessThan": "6.6.91",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.23",
"lessThan": "6.12.29",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.14.2",
"lessThan": "6.14.7",
"versionType": "semver"
}
],
"programFiles": [
"fs/smb/server/oplock.c"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-20T16:15:34.473",
"references": [
{
"url": "https://git.kernel.org/stable/c/2148d34371b06dac696c0497a98a6bf905a51650",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/829e19ef741d9e9932abdc3bee5466195e0852cf",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/af9e2d4732a548db8f6f5a90c2c20a789a3d7240",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eb4447bcce915b43b691123118893fca4f372a8f",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/facf22c1a394c1e023dab5daf9a494f722771e1c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix memory leak in parse_lease_state()\n\nThe previous patch that added bounds check for create lease context\nintroduced a memory leak. When the bounds check fails, the function\nreturns NULL without freeing the previously allocated lease_ctx_info\nstructure.\n\nThis patch fixes the issue by adding kfree(lreq) before returning NULL\nin both boundary check cases."
},
{
"lang": "es",
"value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ksmbd: corrección de fuga de memoria en parse_lease_state(). El parche anterior, que añadía la comprobación de los límites para el contexto de creación de arrendamiento, introducía una fuga de memoria. Cuando la comprobación de los límites falla, la función devuelve NULL sin liberar la estructura lease_ctx_info previamente asignada. Este parche corrige el problema añadiendo kfree(lreq) antes de devolver NULL en ambos casos de comprobación de los límites."
}
],
"lastModified": "2026-06-17T09:15:47.067",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C827BC4-37B0-41DD-81DC-624EE6149EF2",
"versionEndExcluding": "6.1.139",
"versionStartIncluding": "6.1.134"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96DB847D-A07D-4327-BF6F-740CC2F2371F",
"versionEndExcluding": "6.6.91",
"versionStartIncluding": "6.6.87"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57B805A8-4C62-4C40-BCD6-9ED80E3D2784",
"versionEndExcluding": "6.12.29",
"versionStartIncluding": "6.12.23"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "124AE182-7E9F-4410-9E08-5976ED49C6A4",
"versionEndExcluding": "6.14",
"versionStartIncluding": "6.13.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FE133B7-FD40-4BDD-8ADA-DE9782ADC045",
"versionEndExcluding": "6.14.7",
"versionStartIncluding": "6.14.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8D465631-2980-487A-8E65-40AE2B9F8ED1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C9D071F-B28E-46EC-AC61-22B913390211"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13FC0DDE-E513-465E-9E81-515702D49B74"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C7B5B0E-4EEB-48F5-B4CF-0935A7633845"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D240580-3048-49B2-9E27-F115A9DF8224"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}