In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd validates a compound (chained) SMB2 request, ksmbd…
High CVSS 8.2
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd validates a compound (chained) SMB2 request, ksmbd_smb2_check_message() reads pdu->StructureSize2 without first checking that the compound element is large enough to contain it. StructureSize2 is a 2-byte field at offset 64 (__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element. The compound-walking logic only guarantees that a full 64-byte…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877
- https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1
- https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a
- https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb
- https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb
Timeline
- nvd_ingest NVD