Junglewise Threat Intelligence

CVE-2025-21844: Linux Kernel SMB client null pointer dereference in receive_encrypted_standard

CVE-2025-21844 · Severity: medium · CVSS 5.5 · Published 2025-03-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SMB (Server Message Block) client, which is used to connect to network file shares. Under specific conditions, such as low system memory, the system could experience a crash (null pointer dereference) when processing encrypted network traffic. This could lead to a denial-of-service state, impacting the availability of the affected system.

Technical details

A vulnerability exists in the Linux kernel SMB client (CIFS) within the 'receive_encrypted_standard()' function in 'fs/smb/client/smb2ops.c'. The code fails to verify the return values of 'cifs_buf_get()' and 'cifs_small_buf_get()'. If these functions return NULL (typically during memory exhaustion), the subsequent 'memcpy' operation results in a null pointer dereference. An attacker with local access could potentially trigger this condition to cause a kernel panic (Denial of Service). Patches have been released across multiple stable kernel branches to include the necessary null checks.

Affected products

  • Linux Linux Kernel 5.10.211, 5.15.150, 6.1.130, 6.6.80, 6.12.17, 6.13.5

Timeline

  • 2025-03-12: disclosed
  • 2025-03-12: advisory

References

Related threats