#VU109500 Use-after-free in Linux kernel - CVE-2025-37899
Published: May 20, 2025 / Updated: May 23, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a use-after-free error within the smb2_session_logoff() function in fs/smb/server/smb2pdu.c. A remote attacker can send specially crafted data to the SMB client during session logoff and compromise the affected system.