SB20260216133 - Input validation error in Linux kernel smb server
Published: February 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-71220)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the create_smb2_pipe() function in fs/smb/server/smb2pdu.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04dd114b682a4ccaeba2c2bad049c8b50ce740d8
- https://git.kernel.org/stable/c/2b7b4df87fe6f2db6ee45f475de6b37b8b8e5d29
- https://git.kernel.org/stable/c/7c28f8eef5ac5312794d8a52918076dcd787e53b
- https://git.kernel.org/stable/c/a2c68e256fb7a4ac34154c6e865a1389acca839f
- https://git.kernel.org/stable/c/ac18761b530b5dd40f59af8a25902282e5512854
- https://git.kernel.org/stable/c/fdda836fcee6fdbcccc24e3679097efb583f581f