smb: client: Fix next buffer leak in receive_encrypted_standard()
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix next buffer leak in receive_encrypted_standard()
receive_encrypted_standard() allocates next_buffer before checking
whether the number of compound PDUs already reached MAX_COMPOUND. If
the limit check fails, the function returns immediately and the newly
allocated next_buffer is not assigned to server->smallbuf/server->bigbuf,
making it leaked.
Move the MAX_COMPOUND check before allocating next_buffer.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/07e0ab81df1790afa35732a4e8e07ff831b29008https://git.kernel.org/stable/c/1c6267a1d5cf4c73b656f8181b310cbbb3e4767bhttps://git.kernel.org/stable/c/297243e365fc9fe2f8e9b7dd535a65d922cd108bhttps://git.kernel.org/stable/c/67097772df7791c53d608f04bd31c676ccf79b83https://git.kernel.org/stable/c/68fc0b6cc03ca58060c0f36454e169f5fe258974https://git.kernel.org/stable/c/9136a08dc29328edd9867f2545e73906ac9df93bhttps://git.kernel.org/stable/c/927d4805aea0a287d36dd4f826ee24d69a2afee3https://git.kernel.org/stable/c/94e4f672db029414b9888b5137a7559f1febf2d8