CVE-2025-40285
Last modified
CVE-2025-40285 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 37a0e2b362b3150317fb6e2139de67b1e29ae5ff, < 6fc935f798d44a8eb8a5e6659198399fbf57b981; >= 450a844c045ff0895d41b05a1cbe8febd1acfcfd, < e671f9bb97805771380c98de944e2ceab6949188; >= a39e31e22a535d47b14656a7d6a893c7f6cf758c, < dcc51dfe6ff26b52cac106865a172ac982d78401; >= b95629435b84b9ecc0c765995204a4d8a913ed52, < d37b2c81c83d6c0d5ca582f4fe73c672983f9e0d; >= b95629435b84b9ecc0c765995204a4d8a913ed52, < 379510a815cb2e64eb0a379cb62295d6ade65df0; 2107ab40629aeabbec369cf34b8cf0f288c3eb1b; >= 6.1.121, < 6.1.159; >= 6.6.67, < 6.6.117; >= 6.12.6, < 6.12.59; >= 5.15.176, < 5.16 |
| Linux | Linux | 6.13 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40285?
How severe is CVE-2025-40285?
How do I fix CVE-2025-40285?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4028A vulnerability has been found in PHPGurukul COVID19 Testing…9.8
- CVE-2025-40280In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40281In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40282In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2025-40283In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40284In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40286In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40287In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40288In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40289In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4029A vulnerability was found in code-projects Personal Diary Ma…7.8
- CVE-2025-40290In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2025-40285?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
