CVE-2025-39933

Aliases:UBUNTU-CVE-2025-39933DEBIAN-CVE-2025-39933CGA-2969-m3fm-8h24CGA-29x6-3xvw-cpm4CGA-2rj2-vp58-87p9CGA-3358-p337-pp93CGA-33fp-5g63-66vhCGA-37f7-mf4r-jmw6CGA-3p39-4mw8-5936CGA-4fvm-526m-2m73CGA-4j2f-j7xr-x592CGA-546p-fcwg-h8ghCGA-57j3-5m68-v73mCGA-5q6g-347r-wqjqCGA-5x9c-mhmh-w395CGA-648p-m8fm-mf2qCGA-67f3-c734-6fchCGA-72g6-4xrw-52cwCGA-762q-jw4h-mxhqCGA-78xx-f2g9-xc2jCGA-7ccr-gcpm-fcp5CGA-7fw4-wr83-pq4rCGA-7jg7-hhv7-8c3fCGA-7qq3-qm9x-phq3CGA-7whc-76v3-88gvCGA-8673-gcwq-88rhCGA-8796-vw6m-xr64CGA-87qg-6786-77vxCGA-9xfr-4w47-j8jgCGA-cpgm-wc5p-cqwhCGA-crjm-gg35-jjcjCGA-cvj3-c29f-fv38CGA-fgjx-6464-qhcfCGA-fmjj-9chw-8w62CGA-fp38-vf6c-hh48CGA-fwg8-2646-5986CGA-g4m4-46vp-vhmcCGA-g5qp-g57c-227fCGA-gj4c-5q6v-83mxCGA-grfx-j7rx-3qr9CGA-grpq-h42w-pmrmCGA-h5hw-rjpf-grq4CGA-hqp8-4r97-5468CGA-j57f-hx6f-444qCGA-jjfq-rrj4-hc5xCGA-jq6v-gwf6-vmcqCGA-jrfx-g2p2-gxhxCGA-m34v-325r-grmpCGA-m4qw-rr5j-w3x9CGA-m4xf-72jw-w987CGA-pcwp-279m-wj6pCGA-pfrj-c599-x5p8CGA-prx2-38f7-3547CGA-pwqg-cq59-937hCGA-pxjw-7x9w-c82mCGA-q5q7-2qrr-9639CGA-qghc-83p9-4g36CGA-r3gv-5c73-wphjCGA-rh2p-683r-qmrvCGA-rm4r-6vfp-5g8vCGA-rq4j-3mq4-g98mCGA-rvf2-g97x-8j46CGA-v2c9-r3ch-3x8cCGA-v2wc-34vw-p5xfCGA-vmhw-jxcx-3v78CGA-vqfg-mpjw-m857CGA-vrc2-mvjc-76m5CGA-vw4c-qwx6-84w6CGA-vwx2-jwwr-33gvCGA-w7h4-62j7-qqfjCGA-x7c7-vprc-9hjxCGA-x88j-9fv7-v4p5CGA-x9w9-cvpq-gffvCGA-xfv8-jpc9-fr77CGA-xqmj-cx8w-6j5fCGA-xxrh-fq87-cggm
Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 04 Oct 2025, 07:30
Last modified:05 Aug 2026, 12:06

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.4 CRITICAL
v3.1 (cve.org)
EPSS Score
0.21% LOW
0% probability +0.19%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Oct 2025, 07:30
Published
Vulnerability first disclosed
05 Aug 2026, 12:06
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v3.1CRITICALScore: 9.4CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

EPSS Trends

Current EPSS score: 0.21% Percentile: 12%

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.78-r0 | < 6.12.74-r0 | < 6.12.70-r0 | < 6.12.77-r1 | < 6.12.76-r0 | < 6.12.71-r0 | < 6.12.77-r0 | < 6.12.68-r1 | < 6.12.68-r0 | < 6.12.77-r2 | < 6.12.72-r0 | < 6.12.74-r1 | < 6.12.69-r0 | < 6.12.80-r0 | < 6.12.72-r1

  • chainguardlinux-azure-6.12

    < 6.12.72-r0 | < 6.12.77-r0 | < 6.12.70-r0 | < 6.12.71-r0 | < 6.12.74-r0 | < 6.12.68-r0 | < 6.12.78-r0 | < 6.12.77-r2 | < 6.12.74-r1 | < 6.12.80-r0 | < 6.12.76-r0 | < 6.12.69-r0 | < 6.12.77-r1

  • chainguardlinux-gcp-6.12

    < 6.12.74-r1 | < 6.12.68-r0 | < 6.12.70-r0 | < 6.12.76-r0 | < 6.12.77-r0 | < 6.12.68-r1 | < 6.12.72-r0 | < 6.12.74-r0 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.69-r0 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.71-r0

  • chainguardlinux-qemu-6.12

    < 6.12.74-r1 | < 6.12.69-r0 | < 6.12.71-r0 | < 6.12.77-r2 | < 6.12.72-r0 | < 6.12.80-r0 | < 6.12.76-r0 | < 6.12.70-r0 | < 6.12.74-r0 | < 6.12.78-r0 | < 6.12.77-r1 | < 6.12.77-r0 | < 6.12.68-r0

  • chainguardlinux-vmware-6.12

    < 6.12.71-r0 | < 6.12.77-r1 | < 6.12.76-r0 | < 6.12.74-r0 | < 6.12.68-r0 | < 6.12.72-r0 | < 6.12.68-r1 | < 6.12.69-r0 | < 6.12.77-r2 | < 6.12.80-r0 | < 6.12.78-r0 | < 6.12.77-r0 | < 6.12.74-r1 | < 6.12.70-r0

  • debianlinux

    all | all | all | < 6.16.9-1

  • ubuntulinux

    all | all | all

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | all | all

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    all

  • ubuntulinux-aws-fips

    all

  • ubuntulinux-azure

    all | all | all | all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.14

    all

  • ubuntulinux-azure-fde-6.17

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    all

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-azure-nvidia-6.14

    all

  • ubuntulinux-bluefield

    all | all

  • ubuntulinux-fips

    all

  • ubuntulinux-gcp

    all | all | all | all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

Showing first 50 affected entries in server-rendered view.

References (10)