In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix incomplete backport in cfidsinvalidationworker()
The previous commit bdb596ceb4b7 ("smb: client: fix potential UAF in smb2closecachedfid()") was an incomplete backport and missed one krefput() call in cfidsinvalidationworker() that should have been converted to closecacheddir().
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68226.json"
}