Linux Kernel Vulnerability in ksmbd Affects Connection Handling
CVE-2025-38501

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 August 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-38501?

A vulnerability in the ksmbd component of the Linux kernel allows excessive connection attempts from clients with the same IP address. This situation can lead to resource exhaustion, preventing legitimate clients from establishing connections. The recent patch addresses this issue by limiting the number of repeated connections from the same IP, thereby enhancing connection management and improving overall network security.

Affected Version(s)

Linux 0626e6641f6b467447c81dd7678a69c66f7746cf

Linux 0626e6641f6b467447c81dd7678a69c66f7746cf

Linux 0626e6641f6b467447c81dd7678a69c66f7746cf < 7e5d91d3e6c62a9755b36f29c35288f06c3cd86b

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-38501 : Linux Kernel Vulnerability in ksmbd Affects Connection Handling