CVE-2025-21748
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Feb 27, 2025
Updated: Mar 13, 2025
CWE ID 190
Summary
CVE-2025-21748 is a vulnerability affecting the Linux kernel on 32-bit systems. Specifically, an integer overflow issue was identified in the ipc_msg_alloc() function within the ksmbd component. If left unchecked, this overflow could result in memory corruption. To mitigate this risk, the Linux kernel team added bounds checking using KSMBD_IPC_MAX_PAYLOAD, preventing potential integer overflows and subsequent memory corruption.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.