CVE-2025-39942: ksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: smbdirect: verify remainingdatalength respects maxfragmentedrecvsize
This is inspired by the check for dataoffset + datalength.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39942?
CVE-2025-39942 has been classified with a severity rating that depends on the specific impact to affected systems.
How do I fix CVE-2025-39942?
To mitigate CVE-2025-39942, ensure you update the Linux kernel to the latest stable version where the vulnerability has been addressed.
Which systems are affected by CVE-2025-39942?
CVE-2025-39942 affects various versions of the Linux kernel, particularly those utilizing ksmbd for SMB Direct functionality.
What is the nature of the vulnerability in CVE-2025-39942?
CVE-2025-39942 involves a flaw in ksmbd related to verifying data length against the maximum fragmented receive size.
Is there a workaround for CVE-2025-39942?
At this time, applying a kernel update is the primary recommended action, as no specific workaround has been provided.