cbcvebase.
CVE-2025-22043
published 2025-04-16

CVE-2025-22043: In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.45%
36.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.25-1 (forky)linux 6.12.25-1 (forky)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 8d4848c45943c9cf5e86142fd7347efa97f497db8d4848c45943c9cf5e86142fd7347efa97f497db
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 29b946714d6aa77de54c71243bba39469ac43ef229b946714d6aa77de54c71243bba39469ac43ef2
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 1107b9ed92194603593c51829a3887812ae9e8061107b9ed92194603593c51829a3887812ae9e806
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < f0db3d9d416e332a0d6f045a1509539d3a4cd898f0db3d9d416e332a0d6f045a1509539d3a4cd898
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 542027e123fc0bfd61dd59e21ae0ee4ef2101b29542027e123fc0bfd61dd59e21ae0ee4ef2101b29
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.15 < 6.6.876.6.87
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.7 < 6.12.236.12.23
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
rustfsrustfs>= 1.0.0-alpha.13 < 1.0.0-alpha.791.0.0-alpha.79

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
ghsa8.1HIGH
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.