CVE-2025-22074 (GCVE-0-2025-22074)

Vulnerability from cvelistv5 – Published: 2025-04-16 14:12 – Updated: 2026-08-05 11:56
VLAI
Title
ksmbd: fix r_count dec/increment mismatch
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix r_count dec/increment mismatch r_count is only increased when there is an oplock break wait, so r_count inc/decrement are not paired. This can cause r_count to become negative, which can lead to a problem where the ksmbd thread does not terminate.
Impacted products
Vendor Product Version
Linux Linux Affected: 09aeab68033161cb54f194da93e51a11aee6144b , < 4790bcb269e5d6d88200a67c54ae6d627332a3be (git)
Affected: a4261bbc33fbf99b99c80aa3a2c5097611802980 , < 457db486203c90e10c3efc87fd45cc7000b1cd36 (git)
Affected: f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa , < 20378cf48359f39dee0ef9b61470ebe77bd49c0d (git)
Affected: 3aa660c059240e0c795217182cf7df32909dd917 , < c2ec33d46b4d1c8085dab5d02e00b21f4f0fb8a9 (git)
Affected: 3aa660c059240e0c795217182cf7df32909dd917 , < ddb7ea36ba7129c2ed107e2186591128618864e1 (git)
Affected: 6.6.84 , < 6.6.87 (semver)
Affected: 6.12.20 , < 6.12.23 (semver)
Affected: 6.13.8 , < 6.13.11 (semver)
Create a notification for this product.
Linux Linux Affected: 6.14
Unaffected: 0 , < 6.14 (semver)
Unaffected: 6.6.87 , ≤ 6.6.* (semver)
Unaffected: 6.12.23 , ≤ 6.12.* (semver)
Unaffected: 6.13.11 , ≤ 6.13.* (semver)
Unaffected: 6.14.2 , ≤ 6.14.* (semver)
Unaffected: 6.15 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/server/oplock.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4790bcb269e5d6d88200a67c54ae6d627332a3be",
              "status": "affected",
              "version": "09aeab68033161cb54f194da93e51a11aee6144b",
              "versionType": "git"
            },
            {
              "lessThan": "457db486203c90e10c3efc87fd45cc7000b1cd36",
              "status": "affected",
              "version": "a4261bbc33fbf99b99c80aa3a2c5097611802980",
              "versionType": "git"
            },
            {
              "lessThan": "20378cf48359f39dee0ef9b61470ebe77bd49c0d",
              "status": "affected",
              "version": "f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa",
              "versionType": "git"
            },
            {
              "lessThan": "c2ec33d46b4d1c8085dab5d02e00b21f4f0fb8a9",
              "status": "affected",
              "version": "3aa660c059240e0c795217182cf7df32909dd917",
              "versionType": "git"
            },
            {
              "lessThan": "ddb7ea36ba7129c2ed107e2186591128618864e1",
              "status": "affected",
              "version": "3aa660c059240e0c795217182cf7df32909dd917",
              "versionType": "git"
            },
            {
              "lessThan": "6.6.87",
              "status": "affected",
              "version": "6.6.84",
              "versionType": "semver"
            },
            {
              "lessThan": "6.12.23",
              "status": "affected",
              "version": "6.12.20",
              "versionType": "semver"
            },
            {
              "lessThan": "6.13.11",
              "status": "affected",
              "version": "6.13.8",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/server/oplock.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "lessThan": "6.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.87",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.23",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.14.*",
              "status": "unaffected",
              "version": "6.14.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.87",
                  "versionStartIncluding": "6.6.84",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.23",
                  "versionStartIncluding": "6.12.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.11",
                  "versionStartIncluding": "6.13.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14.2",
                  "versionStartIncluding": "6.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15",
                  "versionStartIncluding": "6.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix r_count dec/increment mismatch\n\nr_count is only increased when there is an oplock break wait,\nso r_count inc/decrement are not paired. This can cause r_count\nto become negative, which can lead to a problem where the ksmbd\nthread does not terminate."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - ksmbd is the in-kernel SMB server listening on TCP/445; the oplock/lease break path is driven entirely by SMB2 CREATE/WRITE/SET_INFO requests sent by a remote peer over the network.\nAC:L - The attacker owns both connections involved (the oplock holder and the breaker) and controls exactly how many unbalanced decrements occur by sending N writes, so `r_count` can be steered to zero or negative deterministically; no condition outside the attacker\u0027s control is needed.\nPR:L - Obtaining a level-II oplock or read-caching lease requires an open file handle, which requires a completed SMB2 session setup and tree connect with valid credentials \u2014 a low-privileged authenticated share user suffices.\nUI:N - The attacker triggers the oplock break itself by writing to or truncating the file from a second connection; no action by any local user or administrator is required.\nS:U - The corruption and its consequences (hung ksmbd kthread, freed ksmbd_conn/transport reuse) remain entirely within the kernel\u0027s own security authority.\nC:H - The underflow lets the connection teardown free `ksmbd_conn`, the transport and the socket while an in-flight work item still dereferences them, and the attacker can reoccupy that slab with request-buffer data, yielding a use-after-free read primitive over kernel memory including session keys and credentials.\nI:H - The same use-after-free gives writes through the stale `work-\u003econn`/`work-\u003esess` pointers and via `ksmbd_conn_write()` into freed and reallocated memory, which is the standard basis for heap-spray-driven control-flow hijacking.\nA:H - A negative `r_count` makes `wait_event(conn-\u003er_count_q, r_count == 0)` unsatisfiable, hanging the `ksmbd:%u` kthread uninterruptibly and permanently leaking the socket, connection and sessions; this is repeatable per connection until resources are exhausted, and the UAF variant additionally causes kernel oopses."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:56:32.474Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4790bcb269e5d6d88200a67c54ae6d627332a3be"
        },
        {
          "url": "https://git.kernel.org/stable/c/457db486203c90e10c3efc87fd45cc7000b1cd36"
        },
        {
          "url": "https://git.kernel.org/stable/c/20378cf48359f39dee0ef9b61470ebe77bd49c0d"
        },
        {
          "url": "https://git.kernel.org/stable/c/c2ec33d46b4d1c8085dab5d02e00b21f4f0fb8a9"
        },
        {
          "url": "https://git.kernel.org/stable/c/ddb7ea36ba7129c2ed107e2186591128618864e1"
        }
      ],
      "title": "ksmbd: fix r_count dec/increment mismatch",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-22074",
    "datePublished": "2025-04-16T14:12:25.921Z",
    "dateReserved": "2024-12-29T08:45:45.814Z",
    "dateUpdated": "2026-08-05T11:56:32.474Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2025-22074",
      "date": "2026-10-03",
      "epss": "0.00487",
      "percentile": "0.39729"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "fs/smb/server/oplock.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "4790bcb269e5d6d88200a67c54ae6d627332a3be",
                    "status": "affected",
                    "version": "09aeab68033161cb54f194da93e51a11aee6144b",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "457db486203c90e10c3efc87fd45cc7000b1cd36",
                    "status": "affected",
                    "version": "a4261bbc33fbf99b99c80aa3a2c5097611802980",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "20378cf48359f39dee0ef9b61470ebe77bd49c0d",
                    "status": "affected",
                    "version": "f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "c2ec33d46b4d1c8085dab5d02e00b21f4f0fb8a9",
                    "status": "affected",
                    "version": "3aa660c059240e0c795217182cf7df32909dd917",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ddb7ea36ba7129c2ed107e2186591128618864e1",
                    "status": "affected",
                    "version": "3aa660c059240e0c795217182cf7df32909dd917",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6.6.87",
                    "status": "affected",
                    "version": "6.6.84",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.12.23",
                    "status": "affected",
                    "version": "6.12.20",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.13.11",
                    "status": "affected",
                    "version": "6.13.8",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "fs/smb/server/oplock.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.14"
                  },
                  {
                    "lessThan": "6.14",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.87",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.23",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.13.*",
                    "status": "unaffected",
                    "version": "6.13.11",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.14.*",
                    "status": "unaffected",
                    "version": "6.14.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "6.15",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "configurations": [
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "C840BE22-A881-49E3-8387-B3C767385CFF",
                    "versionEndExcluding": "6.6.87",
                    "versionStartIncluding": "6.6.84",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E6266EAA-36A6-4293-8D0E-E9F7EA2E8341",
                    "versionEndExcluding": "6.12.23",
                    "versionStartIncluding": "6.12.20",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "23B69B03-DE8A-49CE-ADA3-2158636FDDED",
                    "versionEndExcluding": "6.13.11",
                    "versionStartIncluding": "6.13.8",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.14:-:*:*:*:*:*:*",
                    "matchCriteriaId": "7DE421BA-0600-4401-A175-73CAB6A6FB4E",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.14:rc7:*:*:*:*:*:*",
                    "matchCriteriaId": "AD948719-8628-4421-A340-1066314BBD4A",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.14.1:*:*:*:*:*:*:*",
                    "matchCriteriaId": "368D376F-50DC-452F-8D91-2586C7B344FB",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ]
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix r_count dec/increment mismatch\n\nr_count is only increased when there is an oplock break wait,\nso r_count inc/decrement are not paired. This can cause r_count\nto become negative, which can lead to a problem where the ksmbd\nthread does not terminate."
          },
          {
            "lang": "es",
            "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ksmbd: se corrige la discrepancia entre r_count decrement y decrement. r_count solo aumenta cuando hay una espera de interrupci\u00f3n de oplock, por lo que r_count inc/decrement no se empareja. Esto puede provocar que r_count sea negativo, lo que puede provocar un problema donde el subproceso ksmbd no termina."
          }
        ],
        "id": "CVE-2025-22074",
        "lastModified": "2026-07-30T06:22:10.613",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 2.8,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            },
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 3.6,
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        },
        "published": "2025-04-16T15:16:01.593",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "tags": [
              "Patch"
            ],
            "url": "https://git.kernel.org/stable/c/20378cf48359f39dee0ef9b61470ebe77bd49c0d"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "tags": [
              "Patch"
            ],
            "url": "https://git.kernel.org/stable/c/457db486203c90e10c3efc87fd45cc7000b1cd36"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "tags": [
              "Patch"
            ],
            "url": "https://git.kernel.org/stable/c/4790bcb269e5d6d88200a67c54ae6d627332a3be"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "tags": [
              "Patch"
            ],
            "url": "https://git.kernel.org/stable/c/c2ec33d46b4d1c8085dab5d02e00b21f4f0fb8a9"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "tags": [
              "Patch"
            ],
            "url": "https://git.kernel.org/stable/c/ddb7ea36ba7129c2ed107e2186591128618864e1"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Modified",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "NVD-CWE-Other"
              }
            ],
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ]
      }
    },
    "redhat_vex": {
      "aggregate_severity": "None",
      "current_release_date": "2026-06-30T10:24:08+00:00",
      "cve": "CVE-2025-22074",
      "id": "CVE-2025-22074",
      "initial_release_date": "2025-04-16T00:00:00+00:00",
      "product_status:known_not_affected": "274",
      "source": "Red Hat CSAF VEX",
      "status": "final",
      "title": "kernel: ksmbd: fix r_count dec/increment mismatch",
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22074.json",
      "version": "3"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…