CVE-2025-71220: smb/server: call ksmbd_session_rpc_close() on error path in create_smb2_pipe()
Published Feb 14, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
smb/server: call ksmbdsessionrpcclose() on error path in createsmb2pipe()
When ksmbdiovpinrsp() fails, we should call ksmbdsessionrpcclose().
Affected Software
9 affected components
Linux Linux kernel
Linux Linux kernel>=5.15.145<5.15.200
Linux Linux kernel>=6.1.71<6.1.163
Linux Linux kernel>=6.6<6.6.124
Linux Linux kernel>=6.7<6.12.70
Linux Linux kernel>=6.13<6.18.10
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3
Remediation
Event History
Feb 14, 2026
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71220?
CVE-2025-71220 is classified as a medium severity vulnerability.
2
What systems are affected by CVE-2025-71220?
CVE-2025-71220 affects the Linux kernel, specifically in its SMB server functionality.
3
How do I fix CVE-2025-71220?
To mitigate CVE-2025-71220, update your Linux kernel to the latest patched version provided by your distribution.
4
What are the potential impacts of CVE-2025-71220?
Exploitation of CVE-2025-71220 may lead to denial of service or unauthorized access through improper handling of SMB sessions.
5
When was CVE-2025-71220 disclosed?
CVE-2025-71220 was disclosed in 2025, presenting vulnerabilities related to error handling in SMB2 pipe creation.