In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_fill_dirent There is a race condition in the readdir concurrency process, which may acces…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_fill_dirent There is a race condition in the readdir concurrency process, which may access the rsp buffer after it has been released, triggering the following KASAN warning. ================================================================== BUG: KASAN: slab-use-after-free in cifs_fill_dirent+0xb03/0xb60 [cifs] Read of size 4 at addr ffff8880099b819c by task a.out/342975 CPU: 2 UID…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/1b197931fbc821bc7e9e91bf619400db563e3338 Patch
- https://git.kernel.org/stable/c/73cadde98f67f76c5eba00ac0b72c453383cec8b Patch
- https://git.kernel.org/stable/c/9bea368648ac46f8593a780760362e40291d22a9 Patch
- https://git.kernel.org/stable/c/9c9aafbacc183598f064902365e107b5e856531f Patch
- https://git.kernel.org/stable/c/a24c2f05ac3c5b0aaa539d9d913826d2643dfd0e Patch
- https://git.kernel.org/stable/c/a7a8fe56e932a36f43e031b398aef92341bf5ea0 Patch
- https://git.kernel.org/stable/c/aee067e88d61eb72e966f094e4749c6b14e7008f Patch
- https://git.kernel.org/stable/c/c8623231e0edfcccb7cc6add0288fa0f0594282f Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory
Timeline
- nvd_ingest NVD