Linux Kernel CIFS Integer Overflow Vulnerability in acregmax Mount Option

Vulnerability

An integer overflow vulnerability has been identified in the Linux kernel's CIFS (Common Internet File System) implementation. This issue arises when processing the user-provided mount parameter 'acregmax', which is of type u32. The parameter is intended to have an upper limit, but it is converted from seconds to jiffies without proper validation. This conversion can lead to an integer overflow.

Impact

Exploitation of this vulnerability can cause an integer overflow, potentially leading to undefined behavior such as memory corruption.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.