Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
smb/client: fix out-of-bounds read in smb2_compound_op()
If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len.
Then smb2_compound_op() does: memcpy(idata->wsl.eas, data[0], size[0]);
Where size[0] is OutputBufferLength. If iov_len is smaller than size[0], memcpy can read beyond the end of the rsp_iov allocation and leak adjacent kernel heap memory.
Details
- Affected product:
- AlmaLinux 9.2 ESU , TuxCare 9.6 ESU
- Affected packages:
- kernel @ 5.14.0 (+1 more)
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 10 | Released |
44 kernels
|
| AlmaLinux 9 | Released |
80 kernels
|
| Debian 13 | Released |
7 kernels
|
| Oracle Linux 9 | Released |
73 kernels
|
| RHEL 10 | Released |
47 kernels
|
| RHEL 9 | Released |
78 kernels
|
| Rocky Linux 10 | Released |
32 kernels
|
| Rocky Linux 9 | Released |
56 kernels
|