CVE-2025-38501
ksmbd: limit repeated connections from clients with the same IP
- Published
- Aug 16, 2025
- Updated
- Aug 5, 2026
- Assigning CNA
- Linux
- Evidence observed
- Aug 8, 2026
ksmbd: limit repeated connections from clients with the same IP
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.
Proof-of-concept exploit for CVE-2025-38501 that remotely exhausts KSMBD SMB server connection limits via incomplete TCP handshakes, enabling denial-of-service attacks against Linux kernel SMB implementations.
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.