-

CVE-2025-39975

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix wrong index reference in smb2_compound_op()

In smb2_compound_op(), the loop that processes each command's response
uses wrong indices when accessing response bufferes.

This incorrect indexing leads to improper handling of command results.
Also, if incorrectly computed index is greather than or equal to
MAX_COMPOUND, it can cause out-of-bounds accesses.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < ba7bcfd52c66dd1c2dfa5142aca7e4a70b62dfa5
Version 5ddcc9e92d54548219985ce4de88618fb53e14ec
Status affected
Version < bfb1e2aad1fecef8320fd71332acde0d53a8d699
Version efe8db3ecaa40a8520dc9a54283dcecd82ceea9c
Status affected
Version < 093615fc76063ea08d454ba86677ce64c736e806
Version 3681c74d342db75b0d641ba60de27bf73e16e66b
Status affected
Version < fbe2dc6a9c7318f7263f5e4d50f6272b931c5756
Version 3681c74d342db75b0d641ba60de27bf73e16e66b
Status affected
Version 77aefd1d9b790f60634adebbdcfffbe934f41c34
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version < 6.14
Version 0
Status unaffected
Version <= 6.6.*
Version 6.6.109
Status unaffected
Version <= 6.12.*
Version 6.12.50
Status unaffected
Version <= 6.16.*
Version 6.16.10
Status unaffected
Version <= *
Version 6.17
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.059
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String