CVE-2025-38527

smb: client: fix use-after-free in cifs_oplock_break

References

Notes

 carnil> Introduced in b98749cac4a6 ("CIFS: keep FileInfo handle live during oplock
 carnil> break"). Vulnerable versions: 3.16.72 4.9.171 4.14.114 4.19.37 5.0.10 5.1.

Bugs

Status

Branch Status
upstream released (6.16-rc7) [705c79101ccf9edea5a00d761491a03ced314210]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.15-upstream-stable released (6.15.8) [da11bd4b697b393a207f19a2ed7d382a811a3ddc]
6.12-upstream-stable released (6.12.40) [09bce2138a30ef10d8821c8c3f73a4ab7a5726bc]
6.6-upstream-stable released (6.6.100) [2baaf5bbab2ac474c4f92c10fcb3310f824db995]
6.1-upstream-stable released (6.1.147) [0a4eec84d4d2c4085d4ed8630fd74e4b39033c1b]
5.10-upstream-stable needed
sid released (6.16.3-1)
6.12-trixie-security released (6.12.41-1)
6.1-bookworm-security released (6.1.147-1)
5.10-bullseye-security needed