CVE-2025-21660 – Samba Linux Kernel Buffer Use After Free

The following table lists the changes that have been made to the
CVE-2025-21660 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jan. 21, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked

    When `ksmbd_vfs_kern_path_locked` met an error and it is not the last
    entry, it will exit without restoring changed path buffer. But later this
    buffer may be used as the filename for creation.

    Added Reference https://git.kernel.org/stable/c/13e41c58c74baa71f34c0830eaa3c29d53a6e964
    Added Reference https://git.kernel.org/stable/c/2ac538e40278a2c0c051cca81bcaafc547d61372
    Added Reference https://git.kernel.org/stable/c/51669f4af5f7959565b48e55691ba92fabf5c587
    Added Reference https://git.kernel.org/stable/c/65b31b9d992c0fb0685c51a0cf09993832734fc4
Share the Post:

Related Posts