CVE-2025-39943

HIGH

Linux kernel - Out-of-Bounds

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer If data_offset and data_length of smb_direct_data_transfer struct are invalid, out of bounds issue could happen. This patch validate data_offset and data_length field in recv_done.

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (22)
linux/Kernel 5.15.0 - 5.15.194linux
linux/Kernel 5.16.0 - 6.1.154linux
linux/Kernel 6.13.0 - 6.16.9linux
linux/Kernel 6.2.0 - 6.6.108linux
linux/Kernel 6.7.0 - 6.12.49linux
Linux/Linux < 5.15
Linux/Linux 2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 5282491fc49d5614ac6ddcd012e5743eecb6a67c
Linux/Linux 2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 529b121b00a6ee3c88fb3c01b443b2b81f686d48
Linux/Linux 2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 773fddf976d282ef059c36c575ddb81567acd6bc
Linux/Linux 2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 8be498fcbd5b07272f560b45981d4b9e5a2ad885
... and 12 more
Published Oct 04, 2025
Tracked Since Feb 18, 2026