目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-37778— Linux kernel 安全漏洞

AI Predicted 7.8 Difficulty: Moderate EPSS 0.48% · P39

Affected Version Matrix 14

ベンダープロダクトVersion Rangeステータス
LinuxLinux0626e6641f6b467447c81dd7678a69c66f7746cf< b61f04d5d73c53d183019bafe22fb700a739bac5affected
0626e6641f6b467447c81dd7678a69c66f7746cf< d5b554bc8d554ed6ddf443d3db2fad9f665cec10affected
0626e6641f6b467447c81dd7678a69c66f7746cf< 1db2451de23e98bc864c6a6e52aa0d82c91cb325affected
0626e6641f6b467447c81dd7678a69c66f7746cf< 6e30c0e10210c714f3d4453dc258d4abcc70364eaffected
0626e6641f6b467447c81dd7678a69c66f7746cf< e83e39a5f6a01a81411a4558a59a10f87aa88dd6affected
0626e6641f6b467447c81dd7678a69c66f7746cf< 1e440d5b25b7efccb3defe542a73c51005799a5faffected
5.15affected
< 5.15unaffected
… +6 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-37778の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
ksmbd: Fix dangling pointer in krb_authenticate
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix dangling pointer in krb_authenticate krb_authenticate frees sess->user and does not set the pointer to NULL. It calls ksmbd_krb5_authenticate to reinitialise sess->user but that function may return without doing so. If that happens then smb2_sess_setup, which calls krb_authenticate, will be accessing free'd memory when it later uses sess->user.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于krb_authenticate中存在悬垂指针问题。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 0626e6641f6b467447c81dd7678a69c66f7746cf ~ b61f04d5d73c53d183019bafe22fb700a739bac5 -
LinuxLinux 5.15 -

II. CVE-2025-37778の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-37778のインテリジェンス情報

登录查看更多情报信息。

CVE-2025-37778 补丁与修复 (5)

Same Patch Batch · Linux · 2025-05-01 · 245 CVEs total

CVE-2022-49854mctp: Fix an error handling path in mctp_init()
CVE-2022-49837bpf: Fix memory leaks in __check_func_call
CVE-2022-49838sctp: clear out_curr if all frag chunks of current msg are pruned
CVE-2022-49840bpf, test_run: Fix alignment problem in bpf_prog_test_run_skb()
CVE-2022-49839scsi: scsi_transport_sas: Fix error handling in sas_phy_add()
CVE-2022-49841serial: imx: Add missing .thaw_noirq hook
CVE-2022-49842ASoC: core: Fix use-after-free in snd_soc_exit()
CVE-2022-49844can: dev: fix skb drop check
CVE-2022-49845can: j1939: j1939_send_one(): fix missing CAN header initialization
CVE-2022-49846udf: Fix a slab-out-of-bounds write bug in udf_find_entry()
CVE-2022-49847net: ethernet: ti: am65-cpsw: Fix segmentation fault at module unload
CVE-2022-49849btrfs: fix match incorrectly in dev_args_match_device
CVE-2022-49848phy: qcom-qmp-combo: fix NULL-deref on runtime resume
CVE-2022-49850nilfs2: fix deadlock in nilfs_count_free_blocks()
CVE-2022-49851riscv: fix reserved memory setup
CVE-2022-49852riscv: process: fix kernel info leakage
CVE-2022-49862tipc: fix the msg->req tlv len check in tipc_nl_compat_name_table_dump_header
CVE-2022-49864drm/amdkfd: Fix NULL pointer dereference in svm_migrate_to_ram()
CVE-2022-49865ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network
CVE-2022-49863can: af_can: fix NULL pointer dereference in can_rx_register()

Showing 20 of 245 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-37778へのコメント

まだコメントはありません


コメントを残す