CVE-2025-22037

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 29, 2025
CWE ID 476

Summary

CVE-2025-22037 is a vulnerability affecting the Linux kernel, specifically the ksmbd component. Malformed SMB2 negotiate requests from clients can cause a null pointer dereference in alloc_preauth_hash(), resulting in an error response. Subsequently, the client may attempt to send an SMB2 session setup request, even when the pre-auth information is not allocated. This new patch introduces the KSMBD_SESS_NEED_SETUP status for connections, allowing it to ignore session setup requests during the SMB2 negotiate phase.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share