Linux Kernel ksmbd Use-After-Free Vulnerability in Kerberos Authentication

Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel's ksmbd component, specifically within the Kerberos authentication process. The issue arises because the session's user pointer is not properly managed, allowing another thread to access the user data after it has been freed, but before the pointer is reset to NULL. This creates a risk of unintended behavior or memory corruption.

Impact

Exploitation of this vulnerability could lead to memory corruption issues, potentially allowing for arbitrary code execution or causing a denial-of-service condition.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
3.5
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.