In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption…
Critical CVSS 9.1
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception. Track data area…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/36bfa52459e45c0d5b668de2f1c91f6dc5c67775 Patch
- https://git.kernel.org/stable/c/445ece263131780dee273d727a4d6f11934feec7 Patch
- https://git.kernel.org/stable/c/4a9d2657d3e05f6ed09c148cb127b4e58702275f Patch
- https://git.kernel.org/stable/c/57cba95f0e97c6f6e45e6731da30aff091bd7460 Patch
- https://git.kernel.org/stable/c/8986c932905ea508d66da421eb2eb6e676ace1fe Patch
- https://git.kernel.org/stable/c/fdafa1e68dc75045b7b617e6e7d2854950804d83 Patch
Timeline
- nvd_ingest NVD