In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use aeadrequestfree to match aeadrequestalloc
Use aeadrequestfree() instead of kfree() to properly free memory allocated by aeadrequestalloc(). This ensures sensitive crypto data is zeroed before being freed.
[
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ksmbd/auth.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@571b342d4688801fc1f6a1934389dac09425dc93",
"digest": {
"line_hashes": [
"199894311501346911513379622444758463808",
"94696726422140223599693722084386229940",
"315773772354750766614062945922809664249",
"328155162716913159923672413472123258087"
],
"threshold": 0.9
},
"id": "CVE-2025-38575-9d2b5783"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/smb/server/auth.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@aef10ccd74512c52e30c5ee19d0031850973e78d",
"digest": {
"line_hashes": [
"199894311501346911513379622444758463808",
"94696726422140223599693722084386229940",
"315773772354750766614062945922809664249",
"328155162716913159923672413472123258087"
],
"threshold": 0.9
},
"id": "CVE-2025-38575-a2fd14b7"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/smb/server/auth.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6171063e9d046ffa46f51579b2ca4a43caef581a",
"digest": {
"line_hashes": [
"199894311501346911513379622444758463808",
"94696726422140223599693722084386229940",
"315773772354750766614062945922809664249",
"328155162716913159923672413472123258087"
],
"threshold": 0.9
},
"id": "CVE-2025-38575-a8d1a618"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/smb/server/auth.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6b594868268c3a7bfaeced912525cd2c445529a",
"digest": {
"line_hashes": [
"199894311501346911513379622444758463808",
"94696726422140223599693722084386229940",
"315773772354750766614062945922809664249",
"328155162716913159923672413472123258087"
],
"threshold": 0.9
},
"id": "CVE-2025-38575-ded5a147"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/smb/server/auth.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@46caeae23035192b9cc41872c827f30d0233f16e",
"digest": {
"line_hashes": [
"199894311501346911513379622444758463808",
"94696726422140223599693722084386229940",
"315773772354750766614062945922809664249",
"328155162716913159923672413472123258087"
],
"threshold": 0.9
},
"id": "CVE-2025-38575-f5ff791c"
}
]