PT-2025-14327 · Linux+4 · Linux Kernel+4

Published

2025-02-18

·

Updated

2026-05-26

·

CVE-2025-21946

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an out-of-bounds error in the parse sec desc() function within the ksmbd component of the Linux kernel. This occurs when osidoffset, gsidoffset, and dacloffset are greater than the smb ntsd struct size, potentially leading to a slab-out-of-bounds condition. The validation of sid also requires checking its inclusion in the subauth array size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04651
CVE-2025-21946
ECHO-DE49-90A7-564C
OESA-2025-1446
OESA-2025-1450
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7764-1
USN-7764-2
USN-7765-1
USN-7766-1
USN-7767-1
USN-7767-2
USN-7779-1
USN-7790-1
USN-7800-1
USN-7801-1
USN-7801-2
USN-7801-3
USN-7802-1
USN-7809-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Ubuntu