Junglewise Threat Intelligence

CVE-2025-39720: Linux Kernel ksmbd reference count leak in oplock handling

CVE-2025-39720 · Severity: high · CVSS 7.5 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ksmbd component, which provides file-sharing services over a network. A flaw in how the system tracks active connections can lead to a memory leak, where system resources are not properly released after use. Over time, this could allow an attacker to exhaust the server's memory, potentially causing the system to crash or become unresponsive, disrupting business operations.

Technical details

A reference count leak exists in the ksmbd SMB server within the Linux kernel, specifically in the oplock handling logic in 'fs/smb/server/oplock.c'. When the 'ksmbd_conn_releasing' function returns true, the kernel fails to properly decrement the reference count for connection objects ('opinfo->refcount'). This prevents the count from reaching zero, causing the associated memory and resources to remain allocated indefinitely. An attacker can exploit this remotely without authentication to trigger a denial-of-service (DoS) condition via memory exhaustion. Patches have been released for multiple stable kernel branches including 6.6.y, 6.12.y, and 6.16.y.

Affected products

  • Linux Linux Kernel 5.15 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-08-28: patched: Fixes committed to stable kernel trees.
  • 2025-09-05: disclosed: CVE published by NVD.

References

Related threats