{"id":"CVE-2025-22039","title":"ksmbd: fix overflow in dacloffset bounds check","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix overflow in dacloffset bounds check\n\nThe dacloffset field was originally typed as int and used in an\nunchecked addition, which could overflow and bypass the …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < abbb4ec41867f2cd1c971258e493893bf43bcbd3","Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 8483d7b532be1d1bc149556a2fedf903868c6303","Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 73f074fb5e139cd42ad75089abe4e28a49a30003","Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6a9cd9ff0fa2bcc30b2bfb8bdb161eb20e44b9dc","Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6b8d379048b168a0dff5ab1acb975b933f368514","Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 443b373a4df5a2cb9f7b8c4658b2afedeb16397f","Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < beff0bc9d69bc8e733f9bca28e2d3df5b3e10e42","Linux 5.15"],"published":"2025-04-16","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:57:53.618Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-22039","references":[{"url":"https://git.kernel.org/stable/c/abbb4ec41867f2cd1c971258e493893bf43bcbd3"},{"url":"https://git.kernel.org/stable/c/8483d7b532be1d1bc149556a2fedf903868c6303"},{"url":"https://git.kernel.org/stable/c/73f074fb5e139cd42ad75089abe4e28a49a30003"},{"url":"https://git.kernel.org/stable/c/6a9cd9ff0fa2bcc30b2bfb8bdb161eb20e44b9dc"},{"url":"https://git.kernel.org/stable/c/6b8d379048b168a0dff5ab1acb975b933f368514"},{"url":"https://git.kernel.org/stable/c/443b373a4df5a2cb9f7b8c4658b2afedeb16397f"},{"url":"https://git.kernel.org/stable/c/beff0bc9d69bc8e733f9bca28e2d3df5b3e10e42"}],"tags":["cve.org"],"epss":0.00775,"epssPercentile":0.53811,"ingestedAt":"2026-09-14T15:23:07.460Z","slug":"CVE-2025-22039","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix overflow in dacloffset bounds check\n\nThe dacloffset field was originally typed as int and used in an\nunchecked addition, which could overflow and bypass the existing\nbounds check in both smb_check_perm_dacl() and smb_inherit_dacl().\n\nThis could result in out-of-bounds memory access and a kernel crash\nwhen dereferencing the DACL pointer.\n\nThis patch converts dacloffset to unsigned int and uses\ncheck_add_overflow() to validate access to the DACL.\n\n## Affected\n\n- `Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < abbb4ec41867f2cd1c971258e493893bf43bcbd3`\n- `Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 8483d7b532be1d1bc149556a2fedf903868c6303`\n- `Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 73f074fb5e139cd42ad75089abe4e28a49a30003`\n- `Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6a9cd9ff0fa2bcc30b2bfb8bdb161eb20e44b9dc`\n- `Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6b8d379048b168a0dff5ab1acb975b933f368514`\n- `Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 443b373a4df5a2cb9f7b8c4658b2afedeb16397f`\n- `Linux >= 0626e6641f6b467447c81dd7678a69c66f7746cf < beff0bc9d69bc8e733f9bca28e2d3df5b3e10e42`\n- `Linux 5.15`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}