In the Linux kernel, the following vulnerability has been resolved:
cifs: parse_dfs_referrals: prevent oob on malformed input
Malicious SMB server can send invalid reply to FSCTL_DFS_GET_REFERRALS
Processing of such replies will cause oob.
Return -EINVAL error on such replies to prevent oob-s.
No affected software listed.