Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-64380

Опубликовано: 25 июл. 2026
Источник: debian
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed7.1.4-1package
linuxfixed6.12.96-1trixiepackage

Примечания

  • https://git.kernel.org/linus/7ad2bcf2441430bb2e918fb3ef9a90d775a6e422 (7.2-rc2)

EPSS

Процентиль: 36%
0.00443
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.

CVSS3: 7
redhat
7 дней назад

A flaw was found in the Linux kernel's Server Message Block (SMB) client. The vulnerability exists in the `posix_info_sid_size()` function, which is responsible for parsing POSIX Security Identifiers (SIDs). An insufficient boundary check allows the system to accept truncated POSIX SIDs, which could lead to unexpected behavior or a denial of service. This issue has been resolved by requiring at least two bytes before reading the subauthority count, ensuring that all client paths safely reject malformed SIDs.

CVSS3: 8.2
nvd
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.

msrc
6 дней назад

smb: client: harden POSIX SID length parsing

CVSS3: 8.2
github
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.

EPSS

Процентиль: 36%
0.00443
Низкий