{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2025-21660",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2025-21660"
  ],
  "published": "2025-01-21T12:19:12Z",
  "summary": "ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked\n\nWhen `ksmbd_vfs_kern_path_locked` met an error and it is not the last\nentry, it will exit without restoring changed path buffer. But later this\nbuffer may be used as the filename for creation.",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.6.62-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.6.62+rpt-rpi-2712",
            "binary_version": "1:6.6.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.62+rpt-rpi-v6",
            "binary_version": "1:6.6.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.62+rpt-rpi-v7",
            "binary_version": "1:6.6.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.62+rpt-rpi-v7l",
            "binary_version": "1:6.6.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.62+rpt-rpi-v8",
            "binary_version": "1:6.6.62-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.6.62-1+rpt1": {
            "linux_commit": "dd2394360860d15146c96635796a75b05bb32b61",
            "upstream_version": "6.6.62",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.72"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-21660"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/13e41c58c74baa71f34c0830eaa3c29d53a6e964"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/65b31b9d992c0fb0685c51a0cf09993832734fc4"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/51669f4af5f7959565b48e55691ba92fabf5c587"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/2ac538e40278a2c0c051cca81bcaafc547d61372"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-05-24T06:48:58Z"
  }
}
