In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix out-of-bound read in smb2_write
ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If
->NextCommand is bigger than Offset + Length of smb2 write, It will
allow oversized smb2 write length. It will cause OOB read in smb2_write.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linux
Linux linux Kernel |
|
Vendors & Products |
Linux
Linux linux Kernel |
Sat, 16 Aug 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If ->NextCommand is bigger than Offset + Length of smb2 write, It will allow oversized smb2 write length. It will cause OOB read in smb2_write. | |
Title | ksmbd: fix out-of-bound read in smb2_write | |
References |
|

Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2025-08-19T05:47:12.083Z
Reserved: 2023-07-24T14:52:38.053Z
Link: CVE-2023-3865

No data.

Status : Awaiting Analysis
Published: 2025-08-16T14:15:27.250
Modified: 2025-08-18T20:16:28.750
Link: CVE-2023-3865

No data.