Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-64397

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-64397

7 дней назад

A flaw was found in the Linux kernel's ksmbd (kernel Server Message Block daemon) component. Concurrent directory query requests using the same file handle can lead to a stack use-after-free vulnerability. This occurs because smb2_query_dir() stores a pointer to stack-allocated data that can be overwritten by another request while still in use. An attacker could exploit this to cause a denial of service.

EPSS: Низкий
nvd логотип

CVE-2026-64397

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2026-64397

6 дней назад

ksmbd: serialize QUERY_DIRECTORY requests per file

EPSS: Низкий
debian логотип

CVE-2026-64397

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: k ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-76f2-j4c3-m5v4

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-64397

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.

CVSS3: 9.8
0%
Низкий
7 дней назад
redhat логотип
CVE-2026-64397

A flaw was found in the Linux kernel's ksmbd (kernel Server Message Block daemon) component. Concurrent directory query requests using the same file handle can lead to a stack use-after-free vulnerability. This occurs because smb2_query_dir() stores a pointer to stack-allocated data that can be overwritten by another request while still in use. An attacker could exploit this to cause a denial of service.

0%
Низкий
7 дней назад
nvd логотип
CVE-2026-64397

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.

CVSS3: 9.8
0%
Низкий
7 дней назад
msrc логотип
CVE-2026-64397

ksmbd: serialize QUERY_DIRECTORY requests per file

0%
Низкий
6 дней назад
debian логотип
CVE-2026-64397

In the Linux kernel, the following vulnerability has been resolved: k ...

CVSS3: 9.8
0%
Низкий
7 дней назад
github логотип
GHSA-76f2-j4c3-m5v4

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.

CVSS3: 9.8
0%
Низкий
7 дней назад

Уязвимостей на страницу