CVE-2025-39943 — Out-of-bounds Read in Linux
Severity
7.1HIGHNVD
OSV7.8OSV5.5OSV3.2
EPSS
0.0%
top 97.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer
If data_offset and data_length of smb_direct_data_transfer struct are
invalid, out of bounds issue could happen.
This patch validate data_offset and data_length field in recv_done.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2
Affected Packages7 packages
▶CVEListV5linux/linux2ea086e35c3d726a3bacd0a971c1f02a50e98206 — 773fddf976d282ef059c36c575ddb81567acd6bc+6