CVE-2025-22037: Linux Kernel ksmbd Session Setup Null Pointer Dereference Denial-of-Service Vulnerability
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix null pointer dereference in allocpreauthhash()
The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauthinfo is not allocated. This patch add KSMBDSESSNEEDSETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.
Other sources
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable. The specific flaw exists within the handling of preauth hashes. The issue results from dereferencing a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22037?
CVE-2025-22037 has been classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2025-22037?
To fix CVE-2025-22037, update your Linux kernel to version 6.12.23 or later, or ensure you are not using any vulnerable versions between 6.13.0 and 6.14.2.
Which versions of the Linux kernel are affected by CVE-2025-22037?
CVE-2025-22037 affects Linux kernel versions before 6.12.23 and versions between 6.13.0 and 6.14.2.
What causes the vulnerability identified by CVE-2025-22037?
CVE-2025-22037 is caused by a null pointer dereference in the ksmbd component when handling malformed SMB2 negotiate requests.
Can CVE-2025-22037 be exploited remotely?
Yes, CVE-2025-22037 can be exploited remotely by sending specially crafted SMB2 negotiate requests to the affected Linux kernel.