{"id":"CVE-2025-22037","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix null pointer dereference in alloc_preauth_hash()\n\nThe Client send malformed smb2 negotiate request","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix null pointer dereference in alloc_preauth_hash()\n\nThe Client send malformed smb2 negotiate request. ksmbd return error\nresponse. Subsequently, the client can…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.6, < 6.6.107","linux_kernel >= 6.12, < 6.12.23","linux_kernel >= 6.13, < 6.13.11","linux_kernel >= 6.14, < 6.14.2"],"patched":["linux_kernel 6.14.2"],"published":"2025-04-16","updated":"2026-10-08","sourceUpdated":"2026-10-08T00:46:56.740","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-22037","references":[{"url":"https://git.kernel.org/stable/c/8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8eb243e670ecf30e91524dd12f7260dac07d335","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cce57cd8c5dead24127cf2308fdd60fcad2d6ba6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-310/","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.69566,"epssPercentile":0.99351,"zeroDay":true,"ingestedAt":"2026-10-08T01:01:40.722Z","slug":"CVE-2025-22037","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix null pointer dereference in alloc_preauth_hash()\n\nThe Client send malformed smb2 negotiate request. ksmbd return error\nresponse. Subsequently, the client can send smb2 session setup even\nthought conn->preauth_info is not allocated.\nThis patch add KSMBD_SESS_NEED_SETUP status of connection to ignore\nsession setup request if smb2 negotiate phase is not complete.\n\n## Affected\n\n- `linux_kernel >= 6.6, < 6.6.107`\n- `linux_kernel >= 6.12, < 6.12.23`\n- `linux_kernel >= 6.13, < 6.13.11`\n- `linux_kernel >= 6.14, < 6.14.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.14.2`","depth":"abyssal","depthScore":80,"depthScoreParts":{"impact":41.3,"likelihood":13.9,"exploitation":25,"ransomware":0},"changes":[]}