SB2025090863 - NULL pointer dereference in Linux kernel smb server
Published: September 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-39692)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the ksmbd_rdma_init() and ksmbd_rdma_destroy() functions in fs/smb/server/transport_rdma.c, within the ksmbd_conn_transport_destroy() function in fs/smb/server/connection.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/003e6a3150299f681f34cb189aa068018cef6a45
- https://git.kernel.org/stable/c/212eb86f75b4d7b82f3d94aed95ba61103bccb93
- https://git.kernel.org/stable/c/524e90e58a267dad11e23351d9e4b1f941490976
- https://git.kernel.org/stable/c/bac7b996d42e458a94578f4227795a0d4deef6fa
- https://git.kernel.org/stable/c/e41e33400516702427603f8fbbec43c91ede09c0