A newly discussed Linux kernel flaw in the in-kernel SMB server ksmbd has been identified as CVE-2025-37899, a use-after-free bug triggered by a race condition during session handling. Reports say one worker thread can continue using sess->user while another thread processing an SMB2 LOGOFF request frees that structure, creating a path to memory corruption in kernels affected since 5.15. The issue drew attention because ksmbd was introduced in Linux 5.15 and enabled by default from 5.16, potentially widening exposure on systems using the feature.
The disclosure follows earlier reporting on repeated security problems in ksmbd and other Linux networking components, including CVE-2024-26592, CVE-2024-26594, CVE-2023-52440, CVE-2023-52441, and CVE-2023-52442, alongside the nf_tables double-free flaw CVE-2024-1086. Prior discussions highlighted that some vulnerable code paths affected broad kernel ranges and distributions, underscoring a continuing pattern of memory-management bugs in kernel subsystems exposed through SMB and packet-filtering functionality.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A forum discussion published on 2025-05-25 describes CVE-2025-37899, a use-after-free flaw in the Linux kernel's ksmbd component caused by a race between a worker thread using sess->user and an SMB2 LOGOFF handler freeing that structure. The discussion says ksmbd was introduced in Linux 5.15, enabled by default from 5.16, and that kernels from 5.15 onward are affected.
A reference published on 2025-01-29 indicates the Linux kernel received a new release with around 40 changes or fixes. The provided content does not include enough detail to tie this to a specific security event beyond the release itself.
Discussion published on 2024-03-27 references disclosure of multiple Linux kernel flaws, including nf_tables double-free CVE-2024-1086 and several ksmbd issues such as CVE-2024-26592, CVE-2024-26594, CVE-2023-52440, CVE-2023-52441, and CVE-2023-52442. The reports note affected kernel ranges spanning older and newer releases, including ksmbd-related exposure in modern Linux kernels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
opennet.me
Open sourceopennet.ru
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.