CVE-2025-37899 | Linux Kernel up to 6.12.27/6.14.5/6.15-rc4 ksmbd smb2_sess_setup use after free (Nessus ID 242283 / WID-SEC-2025-1114)
A vulnerability was found in Linux Kernel up to 6.12.27/6.14.5/6.15-rc4 and classified as critical. The impacted element is the function smb2_sess_setup of the component ksmbd. Executing manipulation can lead to use after free.
This vulnerability is tracked as CVE-2025-37899. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.