CVE-2025-21946

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21946
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21946.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21946
Downstream
Published
2025-04-01T15:41:08.955Z
Modified
2025-11-28T02:34:29.976085Z
Summary
ksmbd: fix out-of-bounds in parse_sec_desc()
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix out-of-bounds in parsesecdesc()

If osidoffset, gsidoffset and dacloffset could be greater than smb_ntsd struct size. If it is smaller, It could cause slab-out-of-bounds. And when validating sid, It need to check it included subauth array size.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21946.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
c1569dbbe2d43041be9f3fef7ca08bec3b66ad1b
Fixed
159d059cbcb0e6d0e7a7b34af3862ba09a6b22d1
Fixed
6a9831180d0b23b5c97e2bd841aefc8f82900172
Fixed
d6e13e19063db24f94b690159d0633aaf72a0f03

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.6.83
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.19
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.7