CVE-2025-39933
published 2025-10-04CVE-2025-39933: In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
This is inspired by the related server fixes.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.16.9-1 (forky) | linux 6.16.9-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= f198186aa9bbd60fae7a2061f4feec614d880299 < 581fb78e0388b78911b0c920e4073737090c8b5f | 581fb78e0388b78911b0c920e4073737090c8b5f |
| linux | linux | >= f198186aa9bbd60fae7a2061f4feec614d880299 < f57e53ea252363234f86674db475839e5b87102e | f57e53ea252363234f86674db475839e5b87102e |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.16.9-1 | 6.16.9-1 |
| linux | linux_kernel | >= 4.16 < 6.16.9 | 6.16.9 |
| msrc | azl3_kernel_6.6.96.2-2_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vj6-wmm6-q722: In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_len
ghsa_unreviewed·2025-10-04
CVE-2025-39933 [MEDIUM] GHSA-2vj6-wmm6-q722: In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_len
In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
This is inspired by the related server fixes.
OSV
CVE-2025-39933: In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_leng
osv·2025-10-04·CVSS 5.5
CVE-2025-39933 [MEDIUM] CVE-2025-39933: In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_leng
In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.
Microsoft
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
vendor_msrc·2025-10-14·CVSS 5.5
CVE-2025-39933 [MEDIUM] smb: client: let recv_done verify data_offset, data_length and remaining_data_length
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Red Hat
kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2025-39933 [MEDIUM] CWE-787 kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length
kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length
In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
This is inspired by the related server fixes.
Statement: SMB Direct client failed to validate data_offset, data_length, and remaining_data_length in SMBD “data transfer” messages. A malicious server can craft values that cause out-of-bounds access in the kernel receive path, leading to memory corruption and potential code execution.
A malicious SMB Direct server can trigger a kernel crash on a connected and authenticated Linux client by sending malformed data transfer packets over an active RDMA session.
Package: kernel (Red Hat Enterprise Linux
Debian
CVE-2025-39933: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
vendor_debian·2025·CVSS 5.5
CVE-2025-39933 [MEDIUM] CVE-2025-39933: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.16.9-1)
sid: resolved (fixed in 6.16.9-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-39933 kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length
bugzilla·2025-10-04·CVSS 5.5
CVE-2025-39933 [MEDIUM] CVE-2025-39933 kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length
CVE-2025-39933 kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length
In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
This is inspired by the related server fixes.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025100417-CVE-2025-39933-e224@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:0760 https://access.redhat.com/errata/RHSA-2026:0760
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:0759 https://access.redhat.com/errata/RHSA-2026:0759
---
This issue has been addressed in the following pro
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
blogs_bleepingcomputer·2025-10-14·CVSS 7.8
[HIGH] Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Lawrence Abrams
80 Elevation of Privilege Vulnerabilities
11 Security Feature Bypass Vulnerabilities
31 Remote Code Execution Vulnerabilities
28 Information Disclosure Vulnerabilities
11 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released today by Microsoft. Therefore, the number of flaws does not include those fixed in Azure, Mariner, Microsoft Edge, and other vulnerabilities earlier this month.
Notably, Windows 10 reaches the end of support today , with this being the last Patch Tuesday where Microsoft provides free security updates to the venerable operating system.
To continue receiving security upd
2025-10-04
Published