CVE-2025-22037
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauth_info is not allocated. This patch add KSMBD_SESS_NEED_SETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.
- Affected products
- Alt Linux, Astra Linux, Debian, Linuxmint, Linux Kernel, Ubuntu
- Linux Linux Kernel
- < 6.12.23, 6.13.11, 6.14.2
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 66.4% (99th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2025-04-16
CVE-2025-22037 at NVD
No indexed exploits for CVE-2025-22037 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-22037 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.