CVE advisoryCRITICAL
CVE-2025-40099
Linux Kernel CIFS Remote Code Execution Vulnerability CVE-2025-40099
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
A vulnerability in the Linux kernel's CIFS client could allow a malicious SMB server to cause a system crash or unauthorized access to information by sending malformed data. This affects systems using the kernel's file sharing protocol, with potential impacts on service availability and integrity.