CVE-2025-21964

medium

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix integer overflow while processing acregmax mount option User-provided mount parameter acregmax of type u32 is intended to have an upper limit, but before it is validated, the value is converted from seconds to jiffies which can lead to an integer overflow. Found by Linux Verification Center (linuxtesting.org) with SVACE.

References

https://git.kernel.org/stable/c/dd190168e60ac15408f074a1fe0ce36aff34027b

https://git.kernel.org/stable/c/a13351624a6af8d91398860b8c9d4cf6c8e63de5

https://git.kernel.org/stable/c/833f2903eb8b70faca7967319e580e9ce69729fc

https://git.kernel.org/stable/c/7489161b1852390b4413d57f2457cd40b34da6cc

https://git.kernel.org/stable/c/5f500874ab9b3cc8c169c2ab49f00b838520b9c5

https://git.kernel.org/stable/c/0252c33cc943e9e48ddfafaa6b1eb72adb68a099

Details

Source: Mitre, NVD

Published: 2025-04-01

Updated: 2025-04-14

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00018