All findings

CVE-2025-68246, CVE-2025-68811 high

Linux fixes credit ZeroPath on ksmbd and svcrdma CVEs

Linux records say ZeroPath found a remotely triggerable ksmbd resource leak and an svcrdma memory-copy offset error.

Bug class
Remote resource exhaustion and memory-copy boundary error
Affected codebase
Linux ksmbd and svcrdma
Credited system
ZeroPath AI SAST
Disclosed
January 13, 2026
Attribution
Direct source attribution
Severity
high
Source status: Linux CNA descriptions and upstream fix records explicitly state that the bugs were found by ZeroPath.

Summary

CVE-2025-68246 concerns remote socket leakage in ksmbd, allowing a client to consume resources and degrade service. CVE-2025-68811 corrects an offset error in an svcrdma memory copy.

Attribution

These are direct upstream credits. They strengthen ZeroPath’s record beyond self-published Wall of Fame material because Linux’s own public records name the finder workflow.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.