CVE-2025-21748

MEDIUM

Linux Kernel 5.15-6.13.2 - Integer Overflow in ksmbd ipc_msg_alloc

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add bounds checking using KSMBD_IPC_MAX_PAYLOAD to avoid overflow.

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (20)
linux/Kernel 5.15.0 - 5.15.179linux
linux/Kernel 5.16.0 - 6.1.129linux
linux/Kernel 6.13.0 - 6.13.3linux
linux/Kernel 6.2.0 - 6.6.78linux
linux/Kernel 6.7.0 - 6.12.14linux
Linux/Linux < 5.15
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 760568c1f62ea874e8fb492f9cfa4f47b4b8391e
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 82f59d64e6297f270311b16b5dcf65be406d1ea3
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - aab98e2dbd648510f8f51b83fbf4721206ccae45
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - b4b902737746c490258de5cb55cab39e79927a67
... and 10 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026