Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer If data_offset and data_length of smb_direct_data_transfer struct are invalid, out of bounds issue could happen. This patch validate data_offset and data_length field in recv_done.
References (6)
Core 6
Core References
Scores
CVSS v3
7.1
EPSS
0.0002
EPSS Percentile
4.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (22)
linux/Kernel
5.15.0 - 5.15.194linux
linux/Kernel
5.16.0 - 6.1.154linux
linux/Kernel
6.13.0 - 6.16.9linux
linux/Kernel
6.2.0 - 6.6.108linux
linux/Kernel
6.7.0 - 6.12.49linux
Linux/Linux
< 5.15
Linux/Linux
2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 5282491fc49d5614ac6ddcd012e5743eecb6a67c
Linux/Linux
2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 529b121b00a6ee3c88fb3c01b443b2b81f686d48
Linux/Linux
2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 773fddf976d282ef059c36c575ddb81567acd6bc
Linux/Linux
2ea086e35c3d726a3bacd0a971c1f02a50e98206 - 8be498fcbd5b07272f560b45981d4b9e5a2ad885
... and 12 more
Published
Oct 04, 2025
Tracked Since
Feb 18, 2026