CVE-2025-39942

EUVD-2025-32390
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size

This is inspired by the check for data_offset + data_length.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
5.15.1 ≤
𝑥
< 6.1.154
linuxlinux_kernel
6.2 ≤
𝑥
< 6.6.108
linuxlinux_kernel
6.7 ≤
𝑥
< 6.12.49
linuxlinux_kernel
6.13 ≤
𝑥
< 6.16.9
linuxlinux_kernel
5.15
linuxlinux_kernel
5.15:rc7
linuxlinux_kernel
6.17:rc1
linuxlinux_kernel
6.17:rc2
linuxlinux_kernel
6.17:rc3
linuxlinux_kernel
6.17:rc4
linuxlinux_kernel
6.17:rc5
linuxlinux_kernel
6.17:rc6
𝑥
= Vulnerable software versions