In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix out-of-bound read in smb2_write
ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If
->NextCommand is bigger than Offset + Length of smb2 write, It will
allow oversized smb2 write length. It will cause OOB read in smb2_write.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel |
|
| Vendors & Products |
Linux
Linux linux Kernel |
Sat, 16 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If ->NextCommand is bigger than Offset + Length of smb2 write, It will allow oversized smb2 write length. It will cause OOB read in smb2_write. | |
| Title | ksmbd: fix out-of-bound read in smb2_write | |
| References |
|
Status: PUBLISHED
Assigner: Linux
Published: 2025-08-16T13:27:56.403Z
Updated: 2025-08-19T05:47:12.083Z
Reserved: 2023-07-24T14:52:38.053Z
Link: CVE-2023-3865
No data.
Status : Awaiting Analysis
Published: 2025-08-16T14:15:27.250
Modified: 2025-08-18T20:16:28.750
Link: CVE-2023-3865
No data.