CVE-2025-40286
Published Dec 6, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible memory leak in smb2_read() Memory leak occurs when ksmbd_vfs_read() fails. Fix this by adding the missing kvfree().
Is your site exposed to CVE-2025-40286?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0797c6cf3b857cc229ab2bc69552938dcd738d78
https://git.kernel.org/stable/c/63d8706a2c09a0c29b8b0e8a44bc7a1339685de9
https://git.kernel.org/stable/c/6fced056d2cc8d01b326e6fcfabaacb9850b71a4
https://git.kernel.org/stable/c/bfda5422a16651d0bf864ec468b1c216e1b10d91
https://git.kernel.org/stable/c/f1305587731886da37a214cda812ade246c653b0
Frequently Asked Questions
What is CVE-2025-40286? +
In the Linux kernel, the following vulnerability has been resolved:
smb/server: fix possible memory leak in smb2_read()
Memory leak occurs when ksmbd_vfs_read() fails.
Fix this by adding the missing kvfree().
How do I check if I'm vulnerable to CVE-2025-40286? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.