CVE-2025-40285

HIGHCVSS 7.5/10EPSS 0.17%

Last modified

CVE-2025-40285 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.17%

6.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 37a0e2b362b3150317fb6e2139de67b1e29ae5ff, < 6fc935f798d44a8eb8a5e6659198399fbf57b981; >= 450a844c045ff0895d41b05a1cbe8febd1acfcfd, < e671f9bb97805771380c98de944e2ceab6949188; >= a39e31e22a535d47b14656a7d6a893c7f6cf758c, < dcc51dfe6ff26b52cac106865a172ac982d78401; >= b95629435b84b9ecc0c765995204a4d8a913ed52, < d37b2c81c83d6c0d5ca582f4fe73c672983f9e0d; >= b95629435b84b9ecc0c765995204a4d8a913ed52, < 379510a815cb2e64eb0a379cb62295d6ade65df0; 2107ab40629aeabbec369cf34b8cf0f288c3eb1b; >= 6.1.121, < 6.1.159; >= 6.6.67, < 6.6.117; >= 6.12.6, < 6.12.59; >= 5.15.176, < 5.16
LinuxLinux6.13

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-40285?
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().
How severe is CVE-2025-40285?
CVE-2025-40285 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2025-40285?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-40285?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST