-

CVE-2025-39975

smb: client: fix wrong index reference in smb2_compound_op()

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix wrong index reference in smb2_compound_op()

In smb2_compound_op(), the loop that processes each command's response
uses wrong indices when accessing response bufferes.

This incorrect indexing leads to improper handling of command results.
Also, if incorrectly computed index is greather than or equal to
MAX_COMPOUND, it can cause out-of-bounds accesses.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 5ddcc9e92d54548219985ce4de88618fb53e14ec
Version < ba7bcfd52c66dd1c2dfa5142aca7e4a70b62dfa5
Status affected
Version efe8db3ecaa40a8520dc9a54283dcecd82ceea9c
Version < bfb1e2aad1fecef8320fd71332acde0d53a8d699
Status affected
Version 3681c74d342db75b0d641ba60de27bf73e16e66b
Version < 093615fc76063ea08d454ba86677ce64c736e806
Status affected
Version 3681c74d342db75b0d641ba60de27bf73e16e66b
Version < fbe2dc6a9c7318f7263f5e4d50f6272b931c5756
Status affected
Version 77aefd1d9b790f60634adebbdcfffbe934f41c34
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.6.*
Version 6.6.109
Status unaffected
Version <= 6.12.*
Version 6.12.50
Status unaffected
Version <= 6.16.*
Version 6.16.10
Status unaffected
Version <= *
Version 6.17
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.092
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.