CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-40099

Critical · CVSS 9.4
CVSS
9.4
nvd
EPSS
KEV
No
Class
oss containerizable

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed input Malicious SMB server can send invalid reply to FSCTL_DFS_GET_REFERRALS - reply smaller than sizeof(struct get_dfs_referral_rsp) - reply with number of referrals smaller than NumberOfReferrals in the header Processing of such replies will cause oob. Return -EINVAL error on such replies to prevent oob-s.

Affected packages

Linux Kernel 4.11.0 → 6.1.158
Linux Kernel 6.13.0 → 6.17.5
Linux Kernel 6.2.0 → 6.6.114
Linux Kernel 6.7.0 → 6.12.55

References

Status: profiled · ingested 2026-07-30T12:00:00.000Z