In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption…
严重 CVSS 9.1
摘要
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception. Track data area…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/36bfa52459e45c0d5b668de2f1c91f6dc5c67775 Patch
- https://git.kernel.org/stable/c/445ece263131780dee273d727a4d6f11934feec7 Patch
- https://git.kernel.org/stable/c/4a9d2657d3e05f6ed09c148cb127b4e58702275f Patch
- https://git.kernel.org/stable/c/57cba95f0e97c6f6e45e6731da30aff091bd7460 Patch
- https://git.kernel.org/stable/c/8986c932905ea508d66da421eb2eb6e676ace1fe Patch
- https://git.kernel.org/stable/c/fdafa1e68dc75045b7b617e6e7d2854950804d83 Patch
时间线
- nvd_ingest NVD