CVE-2025-38501

In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

17 Mar 2026, 16:04

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.5
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory, Mailing List

13 Feb 2026, 15:58

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/6073afe64510c302b7a0683a01e32c012eff715d - () https://git.kernel.org/stable/c/6073afe64510c302b7a0683a01e32c012eff715d - Patch
References () https://git.kernel.org/stable/c/7e5d91d3e6c62a9755b36f29c35288f06c3cd86b - () https://git.kernel.org/stable/c/7e5d91d3e6c62a9755b36f29c35288f06c3cd86b - Patch
References () https://git.kernel.org/stable/c/cb092fc3a62972a4aa47c9fe356c2c6a01cd840b - () https://git.kernel.org/stable/c/cb092fc3a62972a4aa47c9fe356c2c6a01cd840b - Patch
References () https://git.kernel.org/stable/c/e6bb9193974059ddbb0ce7763fa3882bd60d4dc3 - () https://git.kernel.org/stable/c/e6bb9193974059ddbb0ce7763fa3882bd60d4dc3 - Patch
References () https://git.kernel.org/stable/c/f1ce9258bcbce2491f9f71f7882b6eed0b33ec65 - () https://git.kernel.org/stable/c/f1ce9258bcbce2491f9f71f7882b6eed0b33ec65 - Patch
References () https://git.kernel.org/stable/c/fa1c47af4ff641cf9197ecdb1f8240cbb30389c1 - () https://git.kernel.org/stable/c/fa1c47af4ff641cf9197ecdb1f8240cbb30389c1 - Patch
References () http://www.openwall.com/lists/oss-security/2025/09/15/2 - () http://www.openwall.com/lists/oss-security/2025/09/15/2 - Mailing List
References () https://github.com/keymaker-arch/KSMBDrain - () https://github.com/keymaker-arch/KSMBDrain - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory
First Time Linux
Debian
Debian debian Linux
Linux linux Kernel
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/09/15/2 -

03 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -

30 Oct 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400

15 Sep 2025, 18:15

Type Values Removed Values Added
References
  • () https://github.com/keymaker-arch/KSMBDrain -

18 Aug 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ksmbd: limita las conexiones repetidas de clientes con la misma IP. Las conexiones repetidas de clientes con la misma dirección IP pueden agotar el límite máximo de conexiones e impedir otras conexiones normales de clientes. Este parche limita las conexiones repetidas de clientes con la misma IP.

16 Aug 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-16 06:15

Updated : 2026-03-17 16:04


NVD link : CVE-2025-38501

Mitre link : CVE-2025-38501

CVE.ORG link : CVE-2025-38501


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-400

Uncontrolled Resource Consumption