CVE-2025-68806
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix buffer validation by including null terminator size in EA length
The smb2_set_ea function, which handles Extended Attributes (EA), was performing buffer validation checks that incorrectly omitted the size of the null terminating character (+1 byte) for EA Name. This patch fixes the issue by explicitly adding '+ 1' to EaNameLength where the null terminator is expected to be present in the buffer, ensuring the validation accurately reflects the total required buffer size.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access70 % - Impacto principal
T1005Data from Local Systemcollection65 %
Vulnerabilidad de validación de buffer en ksmbd (SMB en kernel Linux) accesible por red sin autenticación. Permite lectura de datos de memoria mediante procesamiento incorrecto de Extended Attributes.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/6dc8cf6e7998ef7aeb9383a4c2904ea5d22fa2e4
- https://git.kernel.org/stable/c/95d7a890e4b03e198836d49d699408fd1867cb55
- https://git.kernel.org/stable/c/a28a375a5439eb474e9f284509a407efb479c925
- https://git.kernel.org/stable/c/cae52c592a07e1d3fa3338a5f064a374a5f26750
- https://git.kernel.org/stable/c/d26af6d14da43ab92d07bc60437c62901dc522e6
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-68806",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "d070c4dd2a5bed4e9832eec5b6c029c7d14892ea",
"lessThan": "cae52c592a07e1d3fa3338a5f064a374a5f26750",
"versionType": "git"
},
{
"status": "affected",
"version": "0ba5439d9afa2722e7728df56f272c89987540a4",
"lessThan": "a28a375a5439eb474e9f284509a407efb479c925",
"versionType": "git"
},
{
"status": "affected",
"version": "0ba5439d9afa2722e7728df56f272c89987540a4",
"lessThan": "d26af6d14da43ab92d07bc60437c62901dc522e6",
"versionType": "git"
},
{
"status": "affected",
"version": "0ba5439d9afa2722e7728df56f272c89987540a4",
"lessThan": "6dc8cf6e7998ef7aeb9383a4c2904ea5d22fa2e4",
"versionType": "git"
},
{
"status": "affected",
"version": "0ba5439d9afa2722e7728df56f272c89987540a4",
"lessThan": "95d7a890e4b03e198836d49d699408fd1867cb55",
"versionType": "git"
},
{
"status": "affected",
"version": "bb5bf157b5be1643cccc7cbbe57fcdef9ae52c2c",
"versionType": "git"
},
{
"status": "affected",
"version": "1a13ecb96230e8b7b91967e292836f7b01ec8111",
"versionType": "git"
},
{
"status": "affected",
"version": "404e7c01e16288b5e0171d1d8fd3328e806d0794",
"versionType": "git"
},
{
"status": "affected",
"version": "6.1.52",
"lessThan": "6.1.160",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.131",
"lessThan": "5.16",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.4.15",
"lessThan": "6.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.5.2",
"lessThan": "6.6",
"versionType": "semver"
}
],
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.160",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.64",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.3",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-01-13T16:16:02.747",
"references": [
{
"url": "https://git.kernel.org/stable/c/6dc8cf6e7998ef7aeb9383a4c2904ea5d22fa2e4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/95d7a890e4b03e198836d49d699408fd1867cb55",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a28a375a5439eb474e9f284509a407efb479c925",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cae52c592a07e1d3fa3338a5f064a374a5f26750",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d26af6d14da43ab92d07bc60437c62901dc522e6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix buffer validation by including null terminator size in EA length\n\nThe smb2_set_ea function, which handles Extended Attributes (EA),\nwas performing buffer validation checks that incorrectly omitted the size\nof the null terminating character (+1 byte) for EA Name.\nThis patch fixes the issue by explicitly adding '+ 1' to EaNameLength where\nthe null terminator is expected to be present in the buffer, ensuring\nthe validation accurately reflects the total required buffer size."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nksmbd: corrige la validación del búfer al incluir el tamaño del terminador nulo en la longitud de EA\n\nLa función smb2_set_ea, que maneja los Atributos Extendidos (EA),\nestaba realizando comprobaciones de validación del búfer que omitían incorrectamente el tamaño\ndel carácter de terminación nula (+1 byte) para el Nombre de EA.\nEste parche corrige el problema al añadir explícitamente '+ 1' a EaNameLength donde\nse espera que el terminador nulo esté presente en el búfer, asegurando\nque la validación refleje con precisión el tamaño total de búfer requerido."
}
],
"lastModified": "2026-07-30T06:24:46.273",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}