CVE-2026-64381
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked. Move the MAX_COMPOUND check before allocating next_buffer.
Schwachstellenklasse
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked. Move the MAX_COMPOUND check before allocating next_buffer.
Betroffene Produkte
- linux linux_kernel
Quellen
- https://git.kernel.org/stable/c/07e0ab81df1790afa35732a4e8e07ff831b29008
- https://git.kernel.org/stable/c/1c6267a1d5cf4c73b656f8181b310cbbb3e4767b
- https://git.kernel.org/stable/c/297243e365fc9fe2f8e9b7dd535a65d922cd108b
- https://git.kernel.org/stable/c/67097772df7791c53d608f04bd31c676ccf79b83
- https://git.kernel.org/stable/c/68fc0b6cc03ca58060c0f36454e169f5fe258974
- https://git.kernel.org/stable/c/9136a08dc29328edd9867f2545e73906ac9df93b
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.