๐Ÿ” CVE Alert

CVE-2025-40084

UNKNOWN 0.0

ksmbd: transport_ipc: validate payload size before reading handle

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before reading handle handle_response() dereferences the payload as a 4-byte handle without verifying that the declared payload size is at least 4 bytes. A malformed or truncated message from ksmbd.mountd can lead to a 4-byte read past the declared payload size. Validate the size before dereferencing. This is a minimal fix to guard the initial handle read.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 29, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0626e6641f6b467447c81dd7678a69c66f7746cf < a02e432d5130da4c723aabe1205bac805889fdb2 0626e6641f6b467447c81dd7678a69c66f7746cf < 2dc125f5da134c0915a840b62565c60a595673dd 0626e6641f6b467447c81dd7678a69c66f7746cf < 898d527ed94c19980a4d848f10057f1fed578ffb 0626e6641f6b467447c81dd7678a69c66f7746cf < 867ffd9d67285612da3f0498ca618297f8e41f01 0626e6641f6b467447c81dd7678a69c66f7746cf < 6f40e50ceb99fc8ef37e5c56e2ec1d162733fef0
Linux / Linux
5.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a02e432d5130da4c723aabe1205bac805889fdb2 git.kernel.org: https://git.kernel.org/stable/c/2dc125f5da134c0915a840b62565c60a595673dd git.kernel.org: https://git.kernel.org/stable/c/898d527ed94c19980a4d848f10057f1fed578ffb git.kernel.org: https://git.kernel.org/stable/c/867ffd9d67285612da3f0498ca618297f8e41f01 git.kernel.org: https://git.kernel.org/stable/c/6f40e50ceb99fc8ef37e5c56e2ec1d162733fef0