Linux Kernel Vulnerability in SMB3 Affecting CIFS Protocol
CVE-2025-38728

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-38728?

A vulnerability in the Linux kernel's SMB3 implementation has been identified, allowing for a slab out of bounds access during the mounting process with ksmbd. This issue arises from missing checks within the parse_server_interfaces function. If left unaddressed, it can potentially lead to serious memory safety issues, compromising the stability and security of systems utilizing this kernel version. It is crucial for users and administrators to apply appropriate patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9bdb8e98a0073c73ab3e6c631ec78877ceb64565

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8de33d4d72e8fae3502ec3850bd7b14e7c7328b6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-38728 : Linux Kernel Vulnerability in SMB3 Affecting CIFS Protocol