THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-26936

ksmbd: validate request buffer size in smb2_allocate_rsp_buf()

AssignerLinux
Reserved2024-02-19
Published2024-05-01
Updated2024-07-05

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf before validating request. But the fields in payload as well as smb2 header is used in smb2_allocate_rsp_buf(). This patch add simple buffer size validation to avoid potencial out-of-bounds in request buffer.

Product status

Default status
unaffected

1da177e4c3f4 before 8f3d0bf1d0c6
affected

1da177e4c3f4 before 21ff9d7d223c
affected

1da177e4c3f4 before 5c20b242d4fe
affected

1da177e4c3f4 before 2c27a64a2bc4
affected

1da177e4c3f4 before 17cf0c2794bd
affected

Default status
affected

5.15.159
unaffected

6.1.88
unaffected

6.6.29
unaffected

6.8.8
unaffected

6.9
unaffected

References

https://git.kernel.org/stable/c/8f3d0bf1d0c62b539d54c5b9108a845cff619b99

https://git.kernel.org/stable/c/21ff9d7d223c5c19cb4334009e4c0c83a2f4d674

https://git.kernel.org/stable/c/5c20b242d4fed73a93591e48bfd9772e2322fb11

https://git.kernel.org/stable/c/2c27a64a2bc47d9bfc7c3cf8be14be53b1ee7cb6

https://git.kernel.org/stable/c/17cf0c2794bdb6f39671265aa18aea5c22ee8c4a

cve.org CVE-2024-26936

nvd.nist.gov CVE-2024-26936

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-26936
© Copyright 2024 THREATINT. Made in Cyprus with +