CVE-2025-21964

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 14, 2025
CWE ID 190

Summary

CVE-2025-21964 is a recently identified vulnerability in the Linux kernel. This issue lies in the cifs subsystem, where a user-provided mount parameter named 'acregmax' of type u32 is subject to integer overflow. The value of 'acregmax' is initially intended to have an upper limit, but before validation, it gets converted from seconds to jiffies, potentially leading to an integer overflow. This vulnerability was discovered by the Linux Verification Center (linuxtesting.org) and has since been resolved.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share