-

CVE-2025-71120

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf

A zero length gss_token results in pages == 0 and in_token->pages[0]
is NULL. The code unconditionally evaluates
page_address(in_token->pages[0]) for the initial memcpy, which can
dereference NULL even when the copy length is 0. Guard the first
memcpy so it only runs when length > 0.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < a8f1e445ce3545c90d69c9e8ff8f7821825fe810
Version 5866efa8cbfbadf3905072798e96652faf02dbe8
Status affected
Version < 4dedb6a11243a5c9eb9dbb97bca3c98bd725e83d
Version 5866efa8cbfbadf3905072798e96652faf02dbe8
Status affected
Version < f9e53f69ac3bc4ef568b08d3542edac02e83fefd
Version 5866efa8cbfbadf3905072798e96652faf02dbe8
Status affected
Version < 7452d53f293379e2c38cfa8ad0694aa46fc4788b
Version 5866efa8cbfbadf3905072798e96652faf02dbe8
Status affected
Version < a2c6f25ab98b423f99ccd94874d655b8bcb01a19
Version 5866efa8cbfbadf3905072798e96652faf02dbe8
Status affected
Version < 1c8bb965e9b0559ff0f5690615a527c30f651dd8
Version 5866efa8cbfbadf3905072798e96652faf02dbe8
Status affected
Version < d4b69a6186b215d2dc1ebcab965ed88e8d41768d
Version 5866efa8cbfbadf3905072798e96652faf02dbe8
Status affected
Version 66ed7b413d31c6ff23901ac4443b1cc1af2f6113
Status affected
Version 7be8c165dc81564705e8e0b72d398ef708f67eaa
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version < 5.5
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.248
Status unaffected
Version <= 5.15.*
Version 5.15.198
Status unaffected
Version <= 6.1.*
Version 6.1.160
Status unaffected
Version <= 6.6.*
Version 6.6.120
Status unaffected
Version <= 6.12.*
Version 6.12.64
Status unaffected
Version <= 6.18.*
Version 6.18.3
Status unaffected
Version <= *
Version 6.19-rc3
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.