PT-2025-8860 · Linux+6 · Linux Kernel+6

Dan Carpenter

·

Published

2025-01-15

·

Updated

2026-04-20

·

CVE-2025-21748

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to integer overflows in the ksmbd component of the Linux kernel on 32-bit systems. Specifically, the addition operations in the ipc msg alloc() function can potentially overflow, leading to memory corruption. To address this, bounds checking using KSMBD IPC MAX PAYLOAD has been added to prevent overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
AZL-57795
BDU:2025-11912
CVE-2025-21748
DLA-4102-1
OESA-2025-1446
OESA-2025-1450
USN-7510-1
USN-7510-2
USN-7510-3
USN-7510-4
USN-7510-5
USN-7510-6
USN-7510-7
USN-7510-8
USN-7511-1
USN-7511-2
USN-7511-3
USN-7512-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7593-1
USN-7602-1
USN-7651-1
USN-7651-2
USN-7651-3
USN-7651-4
USN-7651-5
USN-7651-6
USN-7652-1
USN-7653-1
USN-7737-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu