CVE-2025-21660Linux vulnerability

37 documents6 sources
Severity
5.5MEDIUMNVD
OSV7.8OSV7.1OSV6.2
EPSS
0.0%
top 91.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21
Latest updateMay 29

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked When `ksmbd_vfs_kern_path_locked` met an error and it is not the last entry, it will exit without restoring changed path buffer. But later this buffer may be used as the filename for creation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel6.1.1136.1.125+4
Debianlinux/linux_kernel< 6.1.128-1+2
Ubuntulinux/linux_kernel< 6.8.0-60.63
CVEListV5linux/linuxd1b2d2a9c912fc7b788985fbaf944e80f4b3f2af13e41c58c74baa71f34c0830eaa3c29d53a6e964+6
debiandebian/linux< linux 6.1.128-1 (bookworm)

Patches

🔴Vulnerability Details

18
OSV
linux-oracle-6.8 vulnerabilities2025-05-29
OSV
linux-hwe-6.8 vulnerabilities2025-05-28
OSV
linux-raspi vulnerabilities2025-05-26
OSV
linux-azure-nvidia vulnerabilities2025-05-20
OSV
linux-raspi-realtime vulnerabilities2025-05-20

📋Vendor Advisories

18
Ubuntu
Linux kernel (Oracle) vulnerabilities2025-05-29
Ubuntu
Linux kernel (HWE) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-26
Ubuntu
Linux kernel vulnerabilities2025-05-20
Ubuntu
Linux kernel (Azure, N-Series) vulnerabilities2025-05-20