CVE-2025-39933: smb: client: let recv_done verify data_offset, data_length and remaining_data_length
Published Oct 4, 2025
·Updated
In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recvdone verify dataoffset, datalength and remainingdatalength
This is inspired by the related server fixes.
Affected Software
8 affected components
Linux Linux kernel
Linux Linux kernel>=4.16<6.16.9
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Linux Linux kernel=6.17-rc3
Linux Linux kernel=6.17-rc4
Linux Linux kernel=6.17-rc5
Linux Linux kernel=6.17-rc6
Event History
Oct 4, 2025
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
DescriptionSeverity
Data Sourced
via Red Hat·08:03 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityAffected Software
Oct 5, 2025
Data Sourced
via Microsoft·01:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-39933?
CVE-2025-39933 has been rated as a high severity vulnerability in the Linux kernel.
2
How do I fix CVE-2025-39933?
To fix CVE-2025-39933, update the Linux kernel to the latest version that includes the security fixes.
3
What is affected by CVE-2025-39933?
CVE-2025-39933 affects the Linux kernel, specifically the SMB client functionality.
4
What are the potential impacts of CVE-2025-39933?
The impacts of CVE-2025-39933 may include vulnerabilities that could allow unauthorized data access or manipulation.
5
Is CVE-2025-39933 exploited in the wild?
As of now, there is no public indication that CVE-2025-39933 is being actively exploited in the wild.