cbcvebase.
CVE-2025-40084
published 2025-10-29

CVE-2025-40084: In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before reading handle handle_response()…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.14%
3.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before reading handle handle_response() dereferences the payload as a 4-byte handle without verifying that the declared payload size is at least 4 bytes. A malformed or truncated message from ksmbd.mountd can lead to a 4-byte read past the declared payload size. Validate the size before dereferencing. This is a minimal fix to guard the initial handle read.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < a02e432d5130da4c723aabe1205bac805889fdb2a02e432d5130da4c723aabe1205bac805889fdb2
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 2dc125f5da134c0915a840b62565c60a595673dd2dc125f5da134c0915a840b62565c60a595673dd
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 898d527ed94c19980a4d848f10057f1fed578ffb898d527ed94c19980a4d848f10057f1fed578ffb
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 867ffd9d67285612da3f0498ca618297f8e41f01867ffd9d67285612da3f0498ca618297f8e41f01
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6f40e50ceb99fc8ef37e5c56e2ec1d162733fef06f40e50ceb99fc8ef37e5c56e2ec1d162733fef0
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.15.0 < 6.1.1586.1.158
linuxlinux_kernel>= 6.13.0 < 6.17.66.17.6
linuxlinux_kernel>= 6.2.0 < 6.6.1156.6.115
linuxlinux_kernel>= 6.7.0 < 6.12.566.12.56
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.