Review reviewHigh

CVE-2025-38488

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in crypt_message when using async crypto The CVE-2024-50047 fix removed asynchronous crypto handling from crypt_message(), assuming all crypto operations are synchronous. However, when hardware crypto accelerators are used, this can cause use-after-free crashes: crypt_message() // Allocate the creq buffer containing the req creq = smb2_get_aead_req(..., &req); // Async encryption returns -EINPROGRESS immediately rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req); // Free creq whil...

CVSS
7.8
EPSS
0.60%
45.5% percentile
CISA KEV
Not listed
Published
2025.07.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.60%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in crypt_message when using async crypto The CVE-2024-50047 fix removed asynchronous crypto handling from crypt_message(), assuming all crypto operations are synchronous. However, when hardware crypto accelerators are used, this can cause use-after-free crashes: crypt_message() // Allocate the creq buffer containing the req creq = smb2_get_aead_req(..., &req); // Async encryption returns -EINPROGRESS immediately rc = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req); // Free creq whil...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 8f14a476abba13144df5434871a7225fd29af633 < 5d047b12f86cc3b9fde1171c02d9bccf4dba0632, >= ef51c0d544b1518b35364480317ab6d3468f205d < 6550b2bef095d0dd2d2c8390d2ea4c3837028833, >= bce966530fd5542bbb422cb45ecb775f7a1a6bc3 < 9a1d3e8d40f151c2d5a5f40c410e6e433f62f438, >= 0809fb86ad13b29e1d6d491364fc7ea4fb545995 < 15a0a5de49507062bc3be4014a403d8cea5533de, >= b0abcd65ec545701b8793e12bc27dc98042b151a < 2a76bc2b24ed889a689fb1c9015307bf16aafb5b, >= b0abcd65ec545701b8793e12bc27dc98042b151a < 8ac90f6824fc44d2e55a82503ddfc95defb19ae0, >= b0abcd65ec545701b8793e12bc27dc98042b151a < b220bed63330c0e1733dc06ea8e75d5b9962b6b6, >= 538c26d9bf70c90edc460d18c81008a4e555925a, >= 5.10.237 < 5.10.241, >= 5.15.181 < 5.15.190, >= 6.1.128 < 6.1.147, >= 6.6.57 < 6.6.100, >= 6.11.4 < 6.12, >= 6.12, >= 6.11.4 < 6.12.40, >= 6.13 < 6.15.8, 6.16, 11.0
Fixed versions
5.10.241, 5.15.190, 6.1.147, 6.6.100, 6.12.40, 6.15.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2025-38488 — Linux Linux, linux kernel, debian linux | SECUFOCUS NOW