CVE-2025-21946: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds in parse_sec_desc() If osidoffset, gsidoffset and dacloffset could be greater than smb_ntsd struct size. If it is smaller, It could cause slab-out-of-bounds. And when validating sid, It need to check it included subauth array size.
Affected products
- Linux Linux Kernel: from 5.15, before 6.6.83 (fixed in 6.6.83); from 6.7, before 6.12.19 (fixed in 6.12.19); from 6.13, before 6.13.7 (fixed in 6.13.7); version 6.14 only
Published 2025-04-01. Last modified 2026-07-30.