CVE-2025-21748: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add bounds checking using KSMBD_IPC_MAX_PAYLOAD to avoid overflow.

Affected products

  • Linux Linux Kernel: from 5.15, before 6.1.129 (fixed in 6.1.129); from 6.2, before 6.6.78 (fixed in 6.6.78); from 6.7, before 6.12.14 (fixed in 6.12.14); from 6.13, before 6.13.3 (fixed in 6.13.3)

Published 2025-02-27. Last modified 2026-07-30.