Bug 2363331 (CVE-2025-37778) - CVE-2025-37778 kernel: ksmbd: Fix dangling pointer in krb_authenticate
Summary: CVE-2025-37778 kernel: ksmbd: Fix dangling pointer in krb_authenticate
Keywords:
Status: NEW
Alias: CVE-2025-37778
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-01 14:04 UTC by OSIDB Bzimport
Modified: 2025-05-02 05:05 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-05-01 14:04:11 UTC
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: Fix dangling pointer in krb_authenticate

krb_authenticate frees sess->user and does not set the pointer
to NULL. It calls ksmbd_krb5_authenticate to reinitialise
sess->user but that function may return without doing so. If
that happens then smb2_sess_setup, which calls krb_authenticate,
will be accessing free'd memory when it later uses sess->user.

Comment 1 Avinash Hanwate 2025-05-02 04:54:33 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025050116-CVE-2025-37778-7202@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.