Review reviewHigh

CVE-2025-40285

Linux

In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().

CVSS
7.5
EPSS
-
- percentile
CISA KEV
Not listed
Published
2025.12.07
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().

Affected product and versions

Product
Linux
Affected versions
>= 37a0e2b362b3150317fb6e2139de67b1e29ae5ff < 6fc935f798d44a8eb8a5e6659198399fbf57b981, >= 450a844c045ff0895d41b05a1cbe8febd1acfcfd < e671f9bb97805771380c98de944e2ceab6949188, >= a39e31e22a535d47b14656a7d6a893c7f6cf758c < dcc51dfe6ff26b52cac106865a172ac982d78401, >= b95629435b84b9ecc0c765995204a4d8a913ed52 < d37b2c81c83d6c0d5ca582f4fe73c672983f9e0d, >= b95629435b84b9ecc0c765995204a4d8a913ed52 < 379510a815cb2e64eb0a379cb62295d6ade65df0, >= 2107ab40629aeabbec369cf34b8cf0f288c3eb1b, >= 6.1.121 < 6.1.159, >= 6.6.67 < 6.6.117, >= 6.12.6 < 6.12.59, >= 5.15.176 < 5.16, >= 6.13
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
Not available