Linux Kernel CIFS Integer Overflow Vulnerability in closetimeo Mount Option

Vulnerability

An integer overflow vulnerability has been identified in the Linux kernel's CIFS (Common Internet File System) implementation. This issue arises when the user-provided mount parameter 'closetimeo', which is of type u32, is converted from seconds to jiffies without proper validation. The lack of validation allows for the possibility of an integer overflow. The vulnerability affects several versions of the Linux kernel.

Impact

Exploitation of this vulnerability can lead to an integer overflow, which may be leveraged to cause unexpected behavior in the system, such as memory corruption or arbitrary code execution.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.