← All CVEs

CVE-2025-21748

critical · 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add bounds checking using KSMBD_IPC_MAX_PAYLOAD to avoid overflow.

9.8
CVSS
0.6%
EPSS (exploit prob.)
47th
EPSS percentile
2025-02-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 5.15, < 6.1.129
linuxlinux_kernel>= 6.2, < 6.6.78
linuxlinux_kernel>= 6.7, < 6.12.14
linuxlinux_kernel>= 6.13, < 6.13.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-21748