cifs: Fix integer overflow while processing closetimeo mount option
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix integer overflow while processing closetimeo mount option
User-provided mount parameter closetimeo of type u32 is intended to have
an upper limit, but before it is validated, the value is converted from
seconds to jiffies which can lead to an integer overflow.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/1c46673be93dd2954f44fe370fb4f2b8e6214224https://git.kernel.org/stable/c/513f6cf2e906a504b7ab0b62b2eea993a6f64558https://git.kernel.org/stable/c/6c13fcb7cf59ae65940da1dfea80144e42921e53https://git.kernel.org/stable/c/9968fcf02cf6b0f78fbacf3f63e782162603855ahttps://git.kernel.org/stable/c/b24edd5c191c2689c59d0509f0903f9487eb6317https://git.kernel.org/stable/c/d5a30fddfe2f2e540f6c43b59cf701809995faefhttps://lists.debian.org/debian-lts-announce/2025/05/msg00045.html