PT-2025-4341 · Linux+4 · Linux Kernel+4

Published

2025-01-06

·

Updated

2025-10-15

·

CVE-2025-21660

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description The issue concerns the ksmbd vfs kern path locked function in the Linux kernel. When this function encounters an error and it is not the last entry, it exits without restoring the changed path buffer. Later, this buffer may be used as the filename for creation, potentially leading to unexpected behavior.
Recommendations For versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ksmbd vfs kern path locked function until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06460
CVE-2025-21660
DLA-4076-1
DSA-5860-1
MGASA-2025-0030
MGASA-2025-0032
OESA-2025-1320
OESA-2025-1321
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7513-1
USN-7513-2
USN-7513-3
USN-7513-4
USN-7513-5
USN-7514-1
USN-7515-1
USN-7515-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu