CVE-2025-21660

MEDIUM EPSS 9.7%
Published Jan 21, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jan 21, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked When `ksmbd_vfs_kern_path_locked` met an error and it is not the last entry, it will exit without restoring changed path buffer. But later this buffer may be used as the filename for creation.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
9.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel*≥6.1.113  –  <6.1.125
linuxlinux_kernel*≥6.6.54  –  <6.6.72
linuxlinux_kernel*≥6.10.13  –  <6.11
linuxlinux_kernel*≥6.11.2  –  <6.12.10
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any

References 5

  • git.kernel.org https://git.kernel.org/stable/c/13e41c58c74baa71f34c0830eaa3c29d53a6e964
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2ac538e40278a2c0c051cca81bcaafc547d61372
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/51669f4af5f7959565b48e55691ba92fabf5c587
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/65b31b9d992c0fb0685c51a0cf09993832734fc4
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/13e41c58c74baa71f34c0830eaa3c29d53a6e964
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2ac538e40278a2c0c051cca81bcaafc547d61372
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/51669f4af5f7959565b48e55691ba92fabf5c587
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/65b31b9d992c0fb0685c51a0cf09993832734fc4
    Patch