CVE-2025-22038

Updated: 2025-05-04 04:15:21.901081

Description:

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_auth[psid->num_subauth - 1] without checking if num_subauth is non-zero leads to an out-of-bounds read. This patch adds a validation step to ensure num_subauth != 0 before sub_auth is accessed.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.1000000000000005

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Not Vulnerable 2025-05-07 04:13:13
AlmaLinux 9.6 ESU kernel 5.14.0 7.1 HIGH Needs Triage 2025-07-03 10:52:47
CentOS 6 ELS kernel 2.6.32 7.1 HIGH Not Vulnerable 2025-05-07 04:13:15
CentOS 7 ELS kernel 3.10.0 7.1 HIGH Not Vulnerable 2025-05-07 04:13:11
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Not Vulnerable 2025-05-07 04:13:14
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Not Vulnerable 2025-05-07 04:13:14
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH Not Vulnerable 2025-05-07 04:13:11
CloudLinux 6 ELS kernel 2.6.32 7.1 HIGH Not Vulnerable 2025-05-07 04:13:15
CloudLinux 7 ELS kernel 3.10.0 7.1 HIGH Not Vulnerable 2025-05-07 04:13:10
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Not Vulnerable 2025-05-07 04:13:11
Total: 17