ThreatCluster

Multiple CVEs Address Use-After-Free Vulnerabilities in ksmbd

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 45

Article Content

Browse articles
ThreatCluster

Two CVEs related to the ksmbd component have been published, addressing use-after-free vulnerabilities. CVE-2025-21945, published on April 1, 2025, affects the smb2_lock function, while CVE-2025-37776, published on May 1, 2025, concerns the smb_break_all_levII_oplock function. These vulnerabilities could potentially impact systems utilizing ksmbd.

Timeline

2025-04-01
CVE-2025-21945 published
2025-05-01
CVE-2025-37776 published
2026-02-18
Information published for CVE-2025-37776
2026-02-18
Information published for CVE-2025-21945