cbcvebase.
CVE-2025-39943
published 2025-10-04

CVE-2025-39943: In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer If…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer If data_offset and data_length of smb_direct_data_transfer struct are invalid, out of bounds issue could happen. This patch validate data_offset and data_length field in recv_done.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 2ea086e35c3d726a3bacd0a971c1f02a50e98206 < 773fddf976d282ef059c36c575ddb81567acd6bc773fddf976d282ef059c36c575ddb81567acd6bc
linuxlinux>= 2ea086e35c3d726a3bacd0a971c1f02a50e98206 < bdaab5c6538e250a9654127e688ecbbeb6f771d5bdaab5c6538e250a9654127e688ecbbeb6f771d5
linuxlinux>= 2ea086e35c3d726a3bacd0a971c1f02a50e98206 < eb0378dde086363046ed3d7db7f126fc3f76fd70eb0378dde086363046ed3d7db7f126fc3f76fd70
linuxlinux>= 2ea086e35c3d726a3bacd0a971c1f02a50e98206 < 8be498fcbd5b07272f560b45981d4b9e5a2ad8858be498fcbd5b07272f560b45981d4b9e5a2ad885
linuxlinux>= 2ea086e35c3d726a3bacd0a971c1f02a50e98206 < 529b121b00a6ee3c88fb3c01b443b2b81f686d48529b121b00a6ee3c88fb3c01b443b2b81f686d48
linuxlinux>= 2ea086e35c3d726a3bacd0a971c1f02a50e98206 < 5282491fc49d5614ac6ddcd012e5743eecb6a67c5282491fc49d5614ac6ddcd012e5743eecb6a67c
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.9-16.16.9-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 5.15.1 < 5.15.1945.15.194
linuxlinux_kernel>= 5.16 < 6.1.1546.1.154
linuxlinux_kernel>= 6.13 < 6.16.96.16.9

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_msrc9.8CRITICAL
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.