Количество 6
Количество 6
CVE-2026-64397
In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.
CVE-2026-64397
A flaw was found in the Linux kernel's ksmbd (kernel Server Message Block daemon) component. Concurrent directory query requests using the same file handle can lead to a stack use-after-free vulnerability. This occurs because smb2_query_dir() stores a pointer to stack-allocated data that can be overwritten by another request while still in use. An attacker could exploit this to cause a denial of service.
CVE-2026-64397
In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.
CVE-2026-64397
ksmbd: serialize QUERY_DIRECTORY requests per file
CVE-2026-64397
In the Linux kernel, the following vulnerability has been resolved: k ...
GHSA-76f2-j4c3-m5v4
In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-64397 In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position. | CVSS3: 9.8 | 0% Низкий | 7 дней назад | |
CVE-2026-64397 A flaw was found in the Linux kernel's ksmbd (kernel Server Message Block daemon) component. Concurrent directory query requests using the same file handle can lead to a stack use-after-free vulnerability. This occurs because smb2_query_dir() stores a pointer to stack-allocated data that can be overwritten by another request while still in use. An attacker could exploit this to cause a denial of service. | 0% Низкий | 7 дней назад | ||
CVE-2026-64397 In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position. | CVSS3: 9.8 | 0% Низкий | 7 дней назад | |
CVE-2026-64397 ksmbd: serialize QUERY_DIRECTORY requests per file | 0% Низкий | 6 дней назад | ||
CVE-2026-64397 In the Linux kernel, the following vulnerability has been resolved: k ... | CVSS3: 9.8 | 0% Низкий | 7 дней назад | |
GHSA-76f2-j4c3-m5v4 In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free. Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position. | CVSS3: 9.8 | 0% Низкий | 7 дней назад |
Уязвимостей на страницу