Bug 2348560 (CVE-2025-21725)
Summary: | CVE-2025-21725 kernel: smb: client: fix oops due to unset link speed | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | dfreiber, drow, jburrell, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A vulnerability was found in the Linux kernel's Server Message Block (SMB) client implementation, specifically within the Common Internet File System (CIFS) module. The issue arises when the client attempts to process network interface information provided by the server, particularly the LinkSpeed parameter. If the server omits this parameter or provides an unexpected value, the client may attempt to perform a division operation with a zero value, leading to a divide-by-zero error and subsequent kernel crash. This misconfiguration on the server could lead to system failure.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
OSIDB Bzimport
2025-02-27 03:03:14 UTC
|