#VU108235 Use-after-free in Linux kernel - CVE-2025-37778


| Updated: 2025-05-23

Vulnerability identifier: #VU108235

Vulnerability risk: High

CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2025-37778

CWE-ID: CWE-416

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a use-after-free error within the krb5_authenticate() function in fs/smb/server/smb2pdu.c. A remote attacker can trick the victim into connecting to a malicious SMB server and execute arbitrary code on the target system.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: 6.14, 6.14.1, 6.14.2, 6.14.3


External links
https://git.kernel.org/stable/c/1db2451de23e98bc864c6a6e52aa0d82c91cb325
https://git.kernel.org/stable/c/1e440d5b25b7efccb3defe542a73c51005799a5f
https://git.kernel.org/stable/c/6e30c0e10210c714f3d4453dc258d4abcc70364e
https://git.kernel.org/stable/c/d5b554bc8d554ed6ddf443d3db2fad9f665cec10
https://git.kernel.org/stable/c/e83e39a5f6a01a81411a4558a59a10f87aa88dd6
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.4


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability