Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in generate_encryptionkey If client send two session setups with krb5 authenticate to ksmbd, null pointer dereference error in generate_encryptionkey could happen. sess->Preauth_HashValue is set to NULL if session is valid. So this patch skip generate encryption key if session is valid.

INFO

Published Date :

2025-08-19T17:02:39.450Z

Last Modified :

2025-08-19T17:02:39.450Z

Source :

Linux
AFFECTED PRODUCTS

The following products are affected by CVE-2025-38562 vulnerability.

Vendors Products
Linux
  • Linux Kernel

CVSS Vulnerability Scoring System