cbcvebase.
CVE-2025-21660
published 2025-01-21

CVE-2025-21660: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked When…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked When `ksmbd_vfs_kern_path_locked` met an error and it is not the last entry, it will exit without restoring changed path buffer. But later this buffer may be used as the filename for creation.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 6.1.113 < 6.1.1256.1.125
linuxlinux>= 6.10.13 < 6.116.11
linuxlinux>= 6.11.2 < 6.126.12
linuxlinux>= 6.6.54 < 6.6.726.6.72
linuxlinux>= 6ab95e27b77730de3fa2d601db3764490c5eede2 < 65b31b9d992c0fb0685c51a0cf09993832734fc465b31b9d992c0fb0685c51a0cf09993832734fc4
linuxlinux>= c5a709f08d40b1a082e44ffcde1aea4d2822ddd5 < 51669f4af5f7959565b48e55691ba92fabf5c58751669f4af5f7959565b48e55691ba92fabf5c587
linuxlinux>= c5a709f08d40b1a082e44ffcde1aea4d2822ddd5 < 2ac538e40278a2c0c051cca81bcaafc547d613722ac538e40278a2c0c051cca81bcaafc547d61372
linuxlinux>= d1b2d2a9c912fc7b788985fbaf944e80f4b3f2af < 13e41c58c74baa71f34c0830eaa3c29d53a6e96413e41c58c74baa71f34c0830eaa3c29d53a6e964
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 6.1.113 < 6.1.1256.1.125
linuxlinux_kernel>= 6.10.13 < 6.116.11
linuxlinux_kernel>= 6.11.2 < 6.12.106.12.10
linuxlinux_kernel>= 6.6.54 < 6.6.726.6.72

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.