296,223
Total vulnerabilities in the database
An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of NameOffset
in the parse_lease_state()
function, the create_context
object can access invalid memory.
Software | From | Fixed in |
---|---|---|
linux / linux_kernel | 6.4-rc1 | 6.4-rc1.x |
linux / linux_kernel | 6.4-rc4 | 6.4-rc4.x |
linux / linux_kernel | 6.4-rc5 | 6.4-rc5.x |
linux / linux_kernel | 6.4-rc2 | 6.4-rc2.x |
linux / linux_kernel | 6.4-rc3 | 6.4-rc3.x |
fedoraproject / fedora | 37 | 37.x |
linux / linux_kernel | 6.2 | 6.3.8 |
linux / linux_kernel | 5.16 | 6.1.34 |
linux / linux_kernel | 5.15 | 5.15.145 |