cbcvebase.
CVE-2025-21946
published 2025-04-01

CVE-2025-21946: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds in parse_sec_desc() If osidoffset, gsidoffset and dacloffset could…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.45%
37.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds in parse_sec_desc() If osidoffset, gsidoffset and dacloffset could be greater than smb_ntsd struct size. If it is smaller, It could cause slab-out-of-bounds. And when validating sid, It need to check it included subauth array size.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < f4ee19528664777af8b842f8f001be98345aa973f4ee19528664777af8b842f8f001be98345aa973
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < c1569dbbe2d43041be9f3fef7ca08bec3b66ad1bc1569dbbe2d43041be9f3fef7ca08bec3b66ad1b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 159d059cbcb0e6d0e7a7b34af3862ba09a6b22d1159d059cbcb0e6d0e7a7b34af3862ba09a6b22d1
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6a9831180d0b23b5c97e2bd841aefc8f829001726a9831180d0b23b5c97e2bd841aefc8f82900172
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < d6e13e19063db24f94b690159d0633aaf72a0f03d6e13e19063db24f94b690159d0633aaf72a0f03
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.15 < 6.6.836.6.83
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.7 < 6.12.196.12.19
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.