cbcvebase.
CVE-2025-21962
published 2025-04-01

CVE-2025-21962: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix integer overflow while processing closetimeo mount option User-provided mount…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix integer overflow while processing closetimeo mount option User-provided mount parameter closetimeo of type u32 is intended to have an upper limit, but before it is validated, the value is converted from seconds to jiffies which can lead to an integer overflow. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 1d9cad9c5873097ea141ffc5da1e7921ce765aa8 < 513f6cf2e906a504b7ab0b62b2eea993a6f64558513f6cf2e906a504b7ab0b62b2eea993a6f64558
linuxlinux>= 5.15.107 < 5.15.1805.15.180
linuxlinux>= 5efdd9122eff772eae2feae9f0fc0ec02d4846a3 < 9968fcf02cf6b0f78fbacf3f63e782162603855a9968fcf02cf6b0f78fbacf3f63e782162603855a
linuxlinux>= 5efdd9122eff772eae2feae9f0fc0ec02d4846a3 < 6c13fcb7cf59ae65940da1dfea80144e42921e536c13fcb7cf59ae65940da1dfea80144e42921e53
linuxlinux>= 5efdd9122eff772eae2feae9f0fc0ec02d4846a3 < 1c46673be93dd2954f44fe370fb4f2b8e62142241c46673be93dd2954f44fe370fb4f2b8e6214224
linuxlinux>= 5efdd9122eff772eae2feae9f0fc0ec02d4846a3 < b24edd5c191c2689c59d0509f0903f9487eb6317b24edd5c191c2689c59d0509f0903f9487eb6317
linuxlinux>= 5efdd9122eff772eae2feae9f0fc0ec02d4846a3 < d5a30fddfe2f2e540f6c43b59cf701809995faefd5a30fddfe2f2e540f6c43b59cf701809995faef
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.15.107 < 5.15.1805.15.180
linuxlinux_kernel>= 6.0 < 6.1.1326.1.132
linuxlinux_kernel>= 6.13 < 6.13.86.13.8
linuxlinux_kernel>= 6.2 < 6.6.846.6.84
linuxlinux_kernel>= 6.7 < 6.12.206.12.20
msrcazl3_kernel_6.6.82.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.85.1-2_on_azure_linux_3.0
msrccbl2_kernel_5.15.176.3-3_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.