In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in async decryption Doing an async decryption (large read) crashes with a slab-use-after-free way down in th…
Critical CVSS 9.8
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in async decryption Doing an async decryption (large read) crashes with a slab-use-after-free way down in the crypto API. Reproducer: # mount.cifs -o ...,seal,esize=1 //srv/share /mnt # dd if=/mnt/largefile of=/dev/null ... [ 194.196391] ================================================================== [ 194.196844] BUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xc1/0x110 …
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/0809fb86ad13b29e1d6d491364fc7ea4fb545995 Patch
- https://git.kernel.org/stable/c/538c26d9bf70c90edc460d18c81008a4e555925a Patch
- https://git.kernel.org/stable/c/8f14a476abba13144df5434871a7225fd29af633
- https://git.kernel.org/stable/c/b0abcd65ec545701b8793e12bc27dc98042b151a Patch
- https://git.kernel.org/stable/c/bce966530fd5542bbb422cb45ecb775f7a1a6bc3
- https://git.kernel.org/stable/c/ef51c0d544b1518b35364480317ab6d3468f205d
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
Timeline
- nvd_ingest NVD