Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-37954— smb: client: Avoid race in open_cached_dir with lease breaks

CVSS 7.5 · High EPSS 0.30% · P22

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux81ba10959970d15c388bf29866b01b62f387e6a3< 2ed98e89ebc2e1bc73534dc3c18cb7843a889ff9affected
81ba10959970d15c388bf29866b01b62f387e6a3< 571dcf3d27b24800c171aea7b5e04ff06d10e2e9affected
81ba10959970d15c388bf29866b01b62f387e6a3< 2407265dc32bc8cc45b62a612c2a214ba9038e8baffected
81ba10959970d15c388bf29866b01b62f387e6a3< 3ca02e63edccb78ef3659bebc68579c7224a6ca2affected
436be190fbf81e5d84040dabf9cb7be06a94dc5daffected
6.5.10< 6.6affected
6.6affected
< 6.6unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-37954

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
smb: client: Avoid race in open_cached_dir with lease breaks
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: Avoid race in open_cached_dir with lease breaks A pre-existing valid cfid returned from find_or_create_cached_dir might race with a lease break, meaning open_cached_dir doesn't consider it valid, and thinks it's newly-constructed. This leaks a dentry reference if the allocation occurs before the queued lease break work runs. Avoid the race by extending holding the cfid_list_lock across find_or_create_cached_dir and when the result is checked.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于smb客户端open_cached_dir与租约中断竞争。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 81ba10959970d15c388bf29866b01b62f387e6a3 ~ 2ed98e89ebc2e1bc73534dc3c18cb7843a889ff9 -
LinuxLinux 6.6 -

II. Public POCs for CVE-2025-37954

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-37954

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-05-20 · 95 CVEs total

CVE-2025-378949.8 CRITICALnet: use sock_gen_put() when sk_state is TCP_TIME_WAIT
CVE-2025-379249.8 CRITICALksmbd: fix use-after-free in kerberos authentication
CVE-2025-379359.8 CRITICALnet: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
CVE-2025-379599.4 CRITICALbpf: Scrub packet on bpf_redirect_peer
CVE-2025-379268.8 HIGHksmbd: fix use-after-free in ksmbd_session_rpc_open
CVE-2025-378998.8 HIGHksmbd: fix use-after-free in session logoff
CVE-2025-379188.8 HIGHBluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()
CVE-2025-379438.8 HIGHwifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi
CVE-2025-379448.8 HIGHwifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process
CVE-2025-379478.8 HIGHksmbd: prevent out-of-bounds stream writes by validating *pos
CVE-2025-379528.8 HIGHksmbd: Fix UAF in __close_file_table_ids
CVE-2025-379568.8 HIGHksmbd: prevent rename with empty string
CVE-2025-379578.8 HIGHKVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
CVE-2025-379368.7 HIGHperf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value.
CVE-2025-379738.1 HIGHwifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation
CVE-2025-379017.8 HIGHirqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs
CVE-2025-379067.8 HIGHublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd
CVE-2025-379217.8 HIGHvxlan: vnifilter: Fix unlocked deletion of default FDB entry
CVE-2025-379237.8 HIGHtracing: Fix oob write in trace_seq_to_buffer()
CVE-2025-379037.8 HIGHdrm/amd/display: Fix slab-use-after-free in hdcp

Showing top 20 of 95 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37954

No comments yet


Leave a comment