PT-2025-14506 · Linux+5 · Linux Kernel+5

Published

2025-02-12

·

Updated

2026-04-20

·

CVE-2025-21994

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns an incorrect validation in the Linux kernel, specifically in the ksmbd component, related to the num aces field of smb acl. The problem arises from the potential to create an excessively large array based on the num aces value, which could lead to issues. The fix involves using the size field of smb acl to properly calculate the actual number of Access Control Entries (ACEs) in the request buffer, thus preventing the allocation of an overly large posix ace state array.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12314
CVE-2025-21994
DLA-4193-1
DSA-5900-1
ECHO-89E3-FC09-0117
MGASA-2025-0142
MGASA-2025-0146
OESA-2025-1446
OESA-2025-1450
USN-7591-1
USN-7591-2
USN-7591-3
USN-7591-4
USN-7591-5
USN-7591-6
USN-7592-1
USN-7593-1
USN-7597-1
USN-7597-2
USN-7598-1
USN-7602-1
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7655-1
USN-7764-1
USN-7764-2
USN-7765-1
USN-7766-1
USN-7767-1
USN-7767-2
USN-7779-1
USN-7790-1
USN-7800-1
USN-7801-1
USN-7801-2
USN-7801-3
USN-7802-1
USN-7809-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu