In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix out-of-bound read in smb2_write
ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If
->NextCommand is bigger than Offset + Length of smb2 write, It will
allow oversized smb2 write length. It will cause OOB read in smb2_write.
Metrics
Affected Vendors & Products
References
History
Sat, 16 Aug 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If ->NextCommand is bigger than Offset + Length of smb2 write, It will allow oversized smb2 write length. It will cause OOB read in smb2_write. | |
Title | ksmbd: fix out-of-bound read in smb2_write | |
References |
|

Status: PUBLISHED
Assigner: Linux
Published: 2025-08-16T13:27:56.403Z
Updated: 2025-08-16T13:27:56.403Z
Reserved: 2023-07-24T14:52:38.053Z
Link: CVE-2023-3865

No data.

Status : Received
Published: 2025-08-16T14:15:27.250
Modified: 2025-08-16T14:15:27.250
Link: CVE-2023-3865

No data.