CVE-2025-40103
Published Oct 30, 2025
Modified Apr 18, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix refcount leak for cifs_sb_tlink Fix three refcount inconsistency issues related to `cifs_sb_tlink`. Comments for `cifs_sb_tlink` state that `cifs_put_tlink()` needs to be called after successful calls to `cifs_sb_tlink()`. Three calls fail to update refcount accordingly, leading to possible resource leaks.
Is your site exposed to CVE-2025-40103?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/790282abe9d805f08618c1c24ea2529e7259b692
https://git.kernel.org/stable/c/896bb31e1416f582503db1350cf1bd10dc64e5a6
https://git.kernel.org/stable/c/c2b77f42205ef485a647f62082c442c1cd69d3fc
https://git.kernel.org/stable/c/d3c8ea197055c260119a13360e8202a27e53e1e4
https://git.kernel.org/stable/c/d7dd034c14928306db1b46be277ae439b84dacf9
https://git.kernel.org/stable/c/e15605b68b490186da2ad8029c0351a9cfb0b9af
Frequently Asked Questions
What is CVE-2025-40103? +
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix refcount leak for cifs_sb_tlink
Fix three refcount inconsistency issues related to `cifs_sb_tlink`.
Comments for `cifs_sb_tlink` state that `cifs_put_tlink()` needs to be
called after successful calls to `cifs_sb_tlink()`. Three calls fail to
update refcount accordingly, leading to possible resource leaks.
How do I check if I'm vulnerable to CVE-2025-40103? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.