Описание
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix next buffer leak in receive_encrypted_standard()
receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked.
Move the MAX_COMPOUND check before allocating next_buffer.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix next buffer leak in receive_encrypted_standard()
receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked.
Move the MAX_COMPOUND check before allocating next_buffer.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-64381
- https://git.kernel.org/stable/c/07e0ab81df1790afa35732a4e8e07ff831b29008
- https://git.kernel.org/stable/c/1c6267a1d5cf4c73b656f8181b310cbbb3e4767b
- https://git.kernel.org/stable/c/297243e365fc9fe2f8e9b7dd535a65d922cd108b
- https://git.kernel.org/stable/c/67097772df7791c53d608f04bd31c676ccf79b83
- https://git.kernel.org/stable/c/68fc0b6cc03ca58060c0f36454e169f5fe258974
- https://git.kernel.org/stable/c/9136a08dc29328edd9867f2545e73906ac9df93b
- https://git.kernel.org/stable/c/927d4805aea0a287d36dd4f826ee24d69a2afee3
- https://git.kernel.org/stable/c/94e4f672db029414b9888b5137a7559f1febf2d8
EPSS
CVE ID
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked. Move the MAX_COMPOUND check before allocating next_buffer.
A flaw was found in the SMB client of the Linux kernel. A remote attacker could exploit a memory leak in the `receive_encrypted_standard()` function by sending specially crafted compound Protocol Data Units (PDUs). This vulnerability occurs because a buffer is allocated before a necessary size check, leading to the buffer not being freed if the check fails. Repeated exploitation of this flaw could lead to a Denial of Service (DoS) due to memory exhaustion.
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked. Move the MAX_COMPOUND check before allocating next_buffer.
In the Linux kernel, the following vulnerability has been resolved: s ...
EPSS