An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely updated after a change from smb30 to smb21.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.13.5 | 4.14.166 |
| linux / linux_kernel | 4.15 | 4.19.73 |
| linux / linux_kernel | 4.20 | 5.0.10 |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |