Junglewise Threat Intelligence

CVE-2025-39975: Linux Kernel out-of-bounds access in SMB client smb2_compound_op

CVE-2025-39975 · Severity: critical · CVSS 9.8 · Published 2025-10-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's SMB client, which is used to connect to network file shares. An error in how the system processes responses from a file server can lead to memory corruption or system instability. This could potentially allow a malicious server to crash the connected system or access sensitive information in memory.

Technical details

An out-of-bounds (OOB) access vulnerability exists in the Linux kernel SMB client within the 'smb2_compound_op()' function in 'fs/smb/client/smb2inode.c'. The root cause is an incorrect index calculation (using 'i + i' instead of 'i + 1') when iterating through response buffers in a loop. This flaw can be triggered when processing compound SMB2 command responses. A malicious or compromised SMB server could exploit this to cause a kernel crash (DoS) or potentially achieve remote code execution by providing crafted responses that exceed the MAX_COMPOUND limit. The issue has been patched in several stable kernel branches including 6.6.109, 6.12.50, and 6.14.

Affected products

  • Linux Linux Kernel 6.6.75 to 6.6.109, 6.12.12 to 6.12.50, 6.13.1 to 6.14

Timeline

  • 2025-09-23: other: Patch authored
  • 2025-10-15: advisory: NVD published date

References

Related threats