Linux · Linux Kernel · CVE-2025-22037
**Name of the Vulnerable Software and Affected Versions**
Linux kernel (affected versions not specified)
**Description**
A null pointer dereference exists in the `alloc preauth hash()` function within the ksmbd module. This occurs when a client sends a malformed SMB2 negotiate request, causing ksmbd to return an error response. If the client subsequently sends an SMB2 session setup request while the `preauth info` variable is not allocated, it can trigger a system crash. This issue can be exploited to cause a denial of service.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.