In the Linux kernel, the following vulnerability has been resolved:
cifs: parsedfsreferrals: prevent oob on malformed input
Malicious SMB server can send invalid reply to FSCTLDFSGET_REFERRALS
Processing of such replies will cause oob.
Return -EINVAL error on such replies to prevent oob-s.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/ee626f5d79d5817bb21d6f048dc0da4c4e383443/cves/2025/40xxx/CVE-2025-40099.json"
}