Back to search
CVE-2025-21946
Published: Apr 1, 2025
Modified: May 11, 2026
PUBLISHED
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds in parse_sec_desc() If osidoffset, gsidoffset and dacloffset could be greater than smb_ntsd struct size. If it is smaller, It could cause slab-out-of-bounds. And when validating sid, It need to check it included subauth array size.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 0626e6641f6b467447c81dd7678a69c66f7746cf - < f4ee19528664777af8b842f8f001be98345aa973affected 0626e6641f6b467447c81dd7678a69c66f7746cf - < c1569dbbe2d43041be9f3fef7ca08bec3b66ad1baffected 0626e6641f6b467447c81dd7678a69c66f7746cf - < 159d059cbcb0e6d0e7a7b34af3862ba09a6b22d1affected 0626e6641f6b467447c81dd7678a69c66f7746cf - < 6a9831180d0b23b5c97e2bd841aefc8f82900172affected 0626e6641f6b467447c81dd7678a69c66f7746cf - < d6e13e19063db24f94b690159d0633aaf72a0f03 |
Linux | Linux | affected 5.15unaffected 0 - < 5.15unaffected 6.1.160 - <= 6.1.*unaffected 6.6.83 - <= 6.6.*unaffected 6.12.19 - <= 6.12.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now