net/smc: check smcd_v2_ext_offset when receiving proposal msg
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
net/smc: check smcd_v2_ext_offset when receiving proposal msg
When receiving proposal msg in server, the field smcd_v2_ext_offset in
proposal msg is from the remote client and can not be fully trusted.
Once the value of smcd_v2_ext_offset exceed the max value, there has
the chance to access wrong address, and crash may happen.
This patch checks the value of smcd_v2_ext_offset before using it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/48d5a8a304a643613dab376a278f29d3e22f7c34https://git.kernel.org/stable/c/935caf324b445fe73d7708fae6f7176fb243f357https://git.kernel.org/stable/c/9ab332deb671d8f7e66d82a2ff2b3f715bc3a4adhttps://git.kernel.org/stable/c/a36364d8d4fabb105001f992fb8ff2d3546203d6https://git.kernel.org/stable/c/e1cc8be2a785a8f1ce1f597f3e608602c5fccd46https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html