We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-21964

cifs: Fix integer overflow while processing acregmax mount option



Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix integer overflow while processing acregmax mount option User-provided mount parameter acregmax of type u32 is intended to have an upper limit, but before it is validated, the value is converted from seconds to jiffies which can lead to an integer overflow. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Reserved 2024-12-29 | Published 2025-04-01 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

5780464614f6abe6026f00cf5a0777aa453ba450 before a13351624a6af8d91398860b8c9d4cf6c8e63de5
affected

5780464614f6abe6026f00cf5a0777aa453ba450 before dd190168e60ac15408f074a1fe0ce36aff34027b
affected

5780464614f6abe6026f00cf5a0777aa453ba450 before 0252c33cc943e9e48ddfafaa6b1eb72adb68a099
affected

5780464614f6abe6026f00cf5a0777aa453ba450 before 833f2903eb8b70faca7967319e580e9ce69729fc
affected

5780464614f6abe6026f00cf5a0777aa453ba450 before 5f500874ab9b3cc8c169c2ab49f00b838520b9c5
affected

5780464614f6abe6026f00cf5a0777aa453ba450 before 7489161b1852390b4413d57f2457cd40b34da6cc
affected

Default status
affected

5.12
affected

Any version before 5.12
unaffected

5.15.180
unaffected

6.1.132
unaffected

6.6.84
unaffected

6.12.20
unaffected

6.13.8
unaffected

6.14
unaffected

References

git.kernel.org/...c/a13351624a6af8d91398860b8c9d4cf6c8e63de5

git.kernel.org/...c/dd190168e60ac15408f074a1fe0ce36aff34027b

git.kernel.org/...c/0252c33cc943e9e48ddfafaa6b1eb72adb68a099

git.kernel.org/...c/833f2903eb8b70faca7967319e580e9ce69729fc

git.kernel.org/...c/5f500874ab9b3cc8c169c2ab49f00b838520b9c5

git.kernel.org/...c/7489161b1852390b4413d57f2457cd40b34da6cc

cve.org (CVE-2025-21964)

nvd.nist.gov (CVE-2025-21964)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-21964

Support options

Helpdesk Chat, Email, Knowledgebase