The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Oracle:9
kernel-uek-modules-extra-netfilter
to version 0:6.12.0-101.33.4.3.el9uek or higher.
This issue was patched in ELSA-2025-20480
.
Note: Versions mentioned in the description apply only to the upstream kernel-uek-modules-extra-netfilter
package and not the kernel-uek-modules-extra-netfilter
package as distributed by Oracle
.
See How to fix?
for Oracle:9
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in SMB request handling
A race condition exists between SMB request handling in
ksmbd_conn_handler_loop()
and the freeing of ksmbd_conn
in the
workqueue handler handle_ksmbd_work()
. This leads to a UAF.
This race condition arises as follows:
ksmbd_conn_handler_loop()
waits for conn->r_count
to reach zero:
wait_event(conn->r_count_q, atomic_read(&conn->r_count) == 0);
handle_ksmbd_work()
decrements conn->r_count
using
atomic_dec_return(&conn->r_count)
, and if it reaches zero, calls
ksmbd_conn_free()
, which frees conn
.handle_ksmbd_work()
decrements conn->r_count
,
it may still access conn->r_count_q
in the following line:
waitqueue_active(&conn->r_count_q)
or wake_up(&conn->r_count_q)
This results in a UAF, as conn
has already been freed.The discovery of this UAF can be referenced in the following PR for syzkaller's support for SMB requests.