CVE-2025-22037: Linux Kernel ksmbd Session Setup Null Pointer Dereference Denial-of-Service Vulnerability

Published Apr 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix null pointer dereference in allocpreauthhash()

The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauthinfo is not allocated. This patch add KSMBDSESSNEEDSETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.

Other sources

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable. The specific flaw exists within the handling of preauth hashes. The issue results from dereferencing a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

— ZDI

Affected Software

6 affected components
Linux Kernel
Linux Kernel
Linux Linux kernel>=6.6<6.6.107
Linux Linux kernel>=6.12<6.12.23
Linux Linux kernel>=6.13<6.13.11
Linux Linux kernel>=6.14<6.14.2

Event History

Apr 16, 2025
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 29, 2025
Advisory Published
via ZDI·12:00 AM
Data Sourced
via ZDI·12:00 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-22037?

CVE-2025-22037 has been classified as a medium severity vulnerability in the Linux kernel.

2

How do I fix CVE-2025-22037?

To fix CVE-2025-22037, update your Linux kernel to version 6.12.23 or later, or ensure you are not using any vulnerable versions between 6.13.0 and 6.14.2.

3

Which versions of the Linux kernel are affected by CVE-2025-22037?

CVE-2025-22037 affects Linux kernel versions before 6.12.23 and versions between 6.13.0 and 6.14.2.

4

What causes the vulnerability identified by CVE-2025-22037?

CVE-2025-22037 is caused by a null pointer dereference in the ksmbd component when handling malformed SMB2 negotiate requests.

5

Can CVE-2025-22037 be exploited remotely?

Yes, CVE-2025-22037 can be exploited remotely by sending specially crafted SMB2 negotiate requests to the affected Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203