Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ksmbd component has been addressed. This issue involved the SMBDirect feature not properly verifying that the remaining data length adhered to the maximum fragmented receive size. The vulnerability could potentially lead to improper buffer handling in data transfers.
The vulnerability could cause buffer validation issues in SMBDirect data transfers, potentially leading to memory corruption or other unintended behavior.
The vulnerability could be reproduced by sending SMBDirect messages that include a remaining data length exceeding the maximum fragmented receive size. This could be done by manipulating the data transfer packets to bypass the intended buffer validation.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.