Description
An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- linux / Kernel4.19 – 5.10.211
- linux / Kernel5.11 – 5.15.150
- linux / Kernel5.16 – 6.1.69
- linux / Kernel6.2 – 6.6.8
- linux / linux_kernel6.1.36 – 6.7
- linux / linux_kernel6.7 – 6.7
- linux / linux_kernel6.7 – 6.7
- linux / linux_kernel6.7 – 6.7
- linux / linux_kernel6.7 – 6.7
- linux / linux_kernel6.7 – 6.7
- netapp / ontap_tools
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:1188
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:1404
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:1532
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:1533
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:1607
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:1614
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:2093
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2024:2394
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2024-0565
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2258518
- MISChttps://www.spinics.net/lists/stable-commits/msg328851.html
Updated 8m ago · 8 sources