CVE-2025-40099: Linux

Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed input Malicious SMB server can send invalid reply to FSCTL_DFS_GET_REFERRALS - reply smaller than sizeof(struct get_dfs_referral_rsp) - reply with number of referrals smaller than NumberOfReferrals in the header Processing of such replies will cause oob. Return -EINVAL error on such replies to prevent oob-s.

Affected products

  • Linux Linux: from 4.11, before 6.1.158 (fixed in 6.1.158); from 6.2, before 6.6.114 (fixed in 6.6.114); from 6.7, before 6.12.55 (fixed in 6.12.55); from 6.13, before 6.17.5 (fixed in 6.17.5)

Published 2025-10-30. Last modified 2026-07-30.