CVE-2025-21844

Source
https://cve.org/CVERecord?id=CVE-2025-21844
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21844.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21844
Downstream
Related
Published
2025-03-12T09:42:00.435Z
Modified
2026-05-07T04:18:07.603757Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
smb: client: Add check for next_buffer in receive_encrypted_standard()
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: Add check for nextbuffer in receiveencrypted_standard()

Add check for the return value of cifsbufget() and cifssmallbufget() in receiveencrypted_standard() to prevent null pointer dereference.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21844.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b03c8099a738a04d2343547ae6a04e5f0f63d3fa
Fixed
f277e479eea3d1aa18bc712abe1d2bf3dece2e30
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
858e73ff25639a0cc1f6f8d2587b62c045867e41
Fixed
f618aeb6cad2307e48a641379db610abcf593edf
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9f528a8e68327117837b5e28b096f52af4c26a05
Fixed
24e8e4523d3071bc5143b0db9127d511489f7b3b
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
534733397da26de0303057ce0b93a22bda150365
Fixed
9e5d99a4cf2e23c716b44862975548415fae5391
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eec04ea119691e65227a97ce53c0da6b9b74b0b7
Fixed
a9b0b4b29877cb4dc5d0842b59b5ccbacddb85bd
Fixed
554736b583f529ee159aa95af9a0cbc12b5ffc96
Fixed
860ca5e50f73c2a1cef7eefc9d39d04e275417f7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21844.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.235
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.179
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.130
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.80
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.17
Fixed
6.13.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21844.json"