CVE-2025-39975
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/10/2025
Last modified:
16/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
smb: client: fix wrong index reference in smb2_compound_op()<br />
<br />
In smb2_compound_op(), the loop that processes each command&#39;s response<br />
uses wrong indices when accessing response bufferes.<br />
<br />
This incorrect indexing leads to improper handling of command results.<br />
Also, if incorrectly computed index is greather than or equal to<br />
MAX_COMPOUND, it can cause out-of-bounds accesses.



