CVE-2025-21844 (GCVE-0-2025-21844)
Vulnerability from cvelistv5
Published
2025-03-12 09:42
Modified
2026-08-05 11:54
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent null pointer dereference.
Impacted products
Vendor Product Version
Linux Linux Version: b03c8099a738a04d2343547ae6a04e5f0f63d3fa
Version: 858e73ff25639a0cc1f6f8d2587b62c045867e41
Version: 9f528a8e68327117837b5e28b096f52af4c26a05
Version: 534733397da26de0303057ce0b93a22bda150365
Version: eec04ea119691e65227a97ce53c0da6b9b74b0b7
Version: eec04ea119691e65227a97ce53c0da6b9b74b0b7
Version: eec04ea119691e65227a97ce53c0da6b9b74b0b7
Version: 5.10.211   
Version: 5.15.150   
Version: 6.1.69   
Version: 6.6.8   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2025-21844",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-01T19:26:41.993251Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-476",
                "description": "CWE-476 NULL Pointer Dereference",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-01T19:36:34.743Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T19:38:00.594Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T12:04:02.128Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "f277e479eea3d1aa18bc712abe1d2bf3dece2e30",
              "status": "affected",
              "version": "b03c8099a738a04d2343547ae6a04e5f0f63d3fa",
              "versionType": "git"
            },
            {
              "lessThan": "f618aeb6cad2307e48a641379db610abcf593edf",
              "status": "affected",
              "version": "858e73ff25639a0cc1f6f8d2587b62c045867e41",
              "versionType": "git"
            },
            {
              "lessThan": "24e8e4523d3071bc5143b0db9127d511489f7b3b",
              "status": "affected",
              "version": "9f528a8e68327117837b5e28b096f52af4c26a05",
              "versionType": "git"
            },
            {
              "lessThan": "9e5d99a4cf2e23c716b44862975548415fae5391",
              "status": "affected",
              "version": "534733397da26de0303057ce0b93a22bda150365",
              "versionType": "git"
            },
            {
              "lessThan": "a9b0b4b29877cb4dc5d0842b59b5ccbacddb85bd",
              "status": "affected",
              "version": "eec04ea119691e65227a97ce53c0da6b9b74b0b7",
              "versionType": "git"
            },
            {
              "lessThan": "554736b583f529ee159aa95af9a0cbc12b5ffc96",
              "status": "affected",
              "version": "eec04ea119691e65227a97ce53c0da6b9b74b0b7",
              "versionType": "git"
            },
            {
              "lessThan": "860ca5e50f73c2a1cef7eefc9d39d04e275417f7",
              "status": "affected",
              "version": "eec04ea119691e65227a97ce53c0da6b9b74b0b7",
              "versionType": "git"
            },
            {
              "lessThan": "5.10.235",
              "status": "affected",
              "version": "5.10.211",
              "versionType": "semver"
            },
            {
              "lessThan": "5.15.179",
              "status": "affected",
              "version": "5.15.150",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1.130",
              "status": "affected",
              "version": "6.1.69",
              "versionType": "semver"
            },
            {
              "lessThan": "6.6.80",
              "status": "affected",
              "version": "6.6.8",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "lessThan": "6.7",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.235",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.179",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.130",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.80",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.17",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.14",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.235",
                  "versionStartIncluding": "5.10.211",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.179",
                  "versionStartIncluding": "5.15.150",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.130",
                  "versionStartIncluding": "6.1.69",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.80",
                  "versionStartIncluding": "6.6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.17",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.5",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Add check for next_buffer in receive_encrypted_standard()\n\nAdd check for the return value of cifs_buf_get() and cifs_small_buf_get()\nin receive_encrypted_standard() to prevent null pointer dereference."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The bug is in the SMB client\u0027s receive path (cifs_demultiplex_thread \u2192 smb3_receive_transform \u2192 receive_encrypted_standard), which parses an encrypted compounded SMB2/SMB3 response arriving from the remote server over TCP/445 or RDMA. The triggering input (a response with a non-zero NextCommand) comes entirely from the remote peer, so the vulnerable code is reached across the network.\nAC:L - A malicious or compromised SMB server reliably reaches the allocation by simply returning a compounded encrypted response with NextCommand set, and can drive the client toward buffer-pool exhaustion with large/compounded responses and many outstanding requests, retrying indefinitely until an allocation fails. No memory-layout or timing condition outside the attacker\u0027s influence is needed.\nPR:N - The attacker is the SMB server (or a compromised legitimate server) and needs no account, credentials, or any privilege level on the victim client system. Nothing on the client-side path performs a privilege check before the demultiplex thread parses the response.\nUI:N - Once a share is mounted \u2014 including long-lived mounts, automounts, or a server that is compromised after the mount \u2014 the server can send the malicious compounded response at any time with no action by any user on the client. Response processing happens asynchronously in the cifsd kernel thread, independent of user activity.\nS:U - The NULL dereference occurs in kernel context on the client and its impact is confined to that kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:N - cifs_buf_get()/cifs_small_buf_get() returning NULL leads to memcpy() into a NULL destination, which faults immediately on the unmapped zero page; no kernel memory is read out or exposed to the attacker.\nI:N - The faulting write targets address 0 and is aborted by the page fault handler, so no kernel data structure is modified and no control-flow hijack primitive is produced.\nA:H - The unchecked NULL dereference causes a kernel oops in the cifsd demultiplex thread, tearing down the connection handling and typically panicking the system (or on panic_on_oops/hardened configurations, halting it), which is a full denial of service."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:54:52.911Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f277e479eea3d1aa18bc712abe1d2bf3dece2e30"
        },
        {
          "url": "https://git.kernel.org/stable/c/f618aeb6cad2307e48a641379db610abcf593edf"
        },
        {
          "url": "https://git.kernel.org/stable/c/24e8e4523d3071bc5143b0db9127d511489f7b3b"
        },
        {
          "url": "https://git.kernel.org/stable/c/9e5d99a4cf2e23c716b44862975548415fae5391"
        },
        {
          "url": "https://git.kernel.org/stable/c/a9b0b4b29877cb4dc5d0842b59b5ccbacddb85bd"
        },
        {
          "url": "https://git.kernel.org/stable/c/554736b583f529ee159aa95af9a0cbc12b5ffc96"
        },
        {
          "url": "https://git.kernel.org/stable/c/860ca5e50f73c2a1cef7eefc9d39d04e275417f7"
        }
      ],
      "title": "smb: client: Add check for next_buffer in receive_encrypted_standard()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-21844",
    "datePublished": "2025-03-12T09:42:00.435Z",
    "dateReserved": "2024-12-29T08:45:45.778Z",
    "dateUpdated": "2026-08-05T11:54:52.911Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T19:38:00.594Z\"}}, {\"affected\": [{\"vendor\": \"Siemens\", \"product\": \"SIMATIC S7-1500 TM MFP - GNU/Linux subsystem\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"*\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unknown\"}], \"x_adpType\": \"supplier\", \"references\": [{\"url\": \"https://cert-portal.siemens.com/productcert/html/ssa-265688.html\"}], \"providerMetadata\": {\"orgId\": \"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e\", \"shortName\": \"siemens-SADP\", \"dateUpdated\": \"2026-05-12T12:04:02.128Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.5, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-21844\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-10-01T19:26:41.993251Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-476\", \"description\": \"CWE-476 NULL Pointer Dereference\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-10-01T16:58:00.670Z\"}}], \"cna\": {\"title\": \"smb: client: Add check for next_buffer in receive_encrypted_standard()\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.5, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The bug is in the SMB client\u0027s receive path (cifs_demultiplex_thread \\u2192 smb3_receive_transform \\u2192 receive_encrypted_standard), which parses an encrypted compounded SMB2/SMB3 response arriving from the remote server over TCP/445 or RDMA. The triggering input (a response with a non-zero NextCommand) comes entirely from the remote peer, so the vulnerable code is reached across the network.\\nAC:L - A malicious or compromised SMB server reliably reaches the allocation by simply returning a compounded encrypted response with NextCommand set, and can drive the client toward buffer-pool exhaustion with large/compounded responses and many outstanding requests, retrying indefinitely until an allocation fails. No memory-layout or timing condition outside the attacker\u0027s influence is needed.\\nPR:N - The attacker is the SMB server (or a compromised legitimate server) and needs no account, credentials, or any privilege level on the victim client system. Nothing on the client-side path performs a privilege check before the demultiplex thread parses the response.\\nUI:N - Once a share is mounted \\u2014 including long-lived mounts, automounts, or a server that is compromised after the mount \\u2014 the server can send the malicious compounded response at any time with no action by any user on the client. Response processing happens asynchronously in the cifsd kernel thread, independent of user activity.\\nS:U - The NULL dereference occurs in kernel context on the client and its impact is confined to that kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\\nC:N - cifs_buf_get()/cifs_small_buf_get() returning NULL leads to memcpy() into a NULL destination, which faults immediately on the unmapped zero page; no kernel memory is read out or exposed to the attacker.\\nI:N - The faulting write targets address 0 and is aborted by the page fault handler, so no kernel data structure is modified and no control-flow hijack primitive is produced.\\nA:H - The unchecked NULL dereference causes a kernel oops in the cifsd demultiplex thread, tearing down the connection handling and typically panicking the system (or on panic_on_oops/hardened configurations, halting it), which is a full denial of service.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"b03c8099a738a04d2343547ae6a04e5f0f63d3fa\", \"lessThan\": \"f277e479eea3d1aa18bc712abe1d2bf3dece2e30\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"858e73ff25639a0cc1f6f8d2587b62c045867e41\", \"lessThan\": \"f618aeb6cad2307e48a641379db610abcf593edf\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f528a8e68327117837b5e28b096f52af4c26a05\", \"lessThan\": \"24e8e4523d3071bc5143b0db9127d511489f7b3b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"534733397da26de0303057ce0b93a22bda150365\", \"lessThan\": \"9e5d99a4cf2e23c716b44862975548415fae5391\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eec04ea119691e65227a97ce53c0da6b9b74b0b7\", \"lessThan\": \"a9b0b4b29877cb4dc5d0842b59b5ccbacddb85bd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eec04ea119691e65227a97ce53c0da6b9b74b0b7\", \"lessThan\": \"554736b583f529ee159aa95af9a0cbc12b5ffc96\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eec04ea119691e65227a97ce53c0da6b9b74b0b7\", \"lessThan\": \"860ca5e50f73c2a1cef7eefc9d39d04e275417f7\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5.10.211\", \"lessThan\": \"5.10.235\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.15.150\", \"lessThan\": \"5.15.179\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.1.69\", \"lessThan\": \"6.1.130\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.6.8\", \"lessThan\": \"6.6.80\", \"versionType\": \"semver\"}], \"programFiles\": [\"fs/smb/client/smb2ops.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.7\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.7\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.235\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.179\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.130\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.80\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.17\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.13.5\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.13.*\"}, {\"status\": \"unaffected\", \"version\": \"6.14\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/smb/client/smb2ops.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/f277e479eea3d1aa18bc712abe1d2bf3dece2e30\"}, {\"url\": \"https://git.kernel.org/stable/c/f618aeb6cad2307e48a641379db610abcf593edf\"}, {\"url\": \"https://git.kernel.org/stable/c/24e8e4523d3071bc5143b0db9127d511489f7b3b\"}, {\"url\": \"https://git.kernel.org/stable/c/9e5d99a4cf2e23c716b44862975548415fae5391\"}, {\"url\": \"https://git.kernel.org/stable/c/a9b0b4b29877cb4dc5d0842b59b5ccbacddb85bd\"}, {\"url\": \"https://git.kernel.org/stable/c/554736b583f529ee159aa95af9a0cbc12b5ffc96\"}, {\"url\": \"https://git.kernel.org/stable/c/860ca5e50f73c2a1cef7eefc9d39d04e275417f7\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nsmb: client: Add check for next_buffer in receive_encrypted_standard()\\n\\nAdd check for the return value of cifs_buf_get() and cifs_small_buf_get()\\nin receive_encrypted_standard() to prevent null pointer dereference.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.235\", \"versionStartIncluding\": \"5.10.211\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.179\", \"versionStartIncluding\": \"5.15.150\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.130\", \"versionStartIncluding\": \"6.1.69\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.80\", \"versionStartIncluding\": \"6.6.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.17\", \"versionStartIncluding\": \"6.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.13.5\", \"versionStartIncluding\": \"6.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.14\", \"versionStartIncluding\": \"6.7\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:54:52.911Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-21844\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:54:52.911Z\", \"dateReserved\": \"2024-12-29T08:45:45.778Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-03-12T09:42:00.435Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…