Home

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer If data_offset and data_length of smb_direct_data_transfer struct are invalid, out of bounds issue could happen. This patch validate data_offset and data_length field in recv_done.

PUBLISHED Reserved 2025-04-16 | Published 2025-10-04 | Updated 2025-10-04 | Assigner Linux

Product status

Default status
unaffected

2ea086e35c3d726a3bacd0a971c1f02a50e98206 before 773fddf976d282ef059c36c575ddb81567acd6bc
affected

2ea086e35c3d726a3bacd0a971c1f02a50e98206 before bdaab5c6538e250a9654127e688ecbbeb6f771d5
affected

2ea086e35c3d726a3bacd0a971c1f02a50e98206 before eb0378dde086363046ed3d7db7f126fc3f76fd70
affected

2ea086e35c3d726a3bacd0a971c1f02a50e98206 before 8be498fcbd5b07272f560b45981d4b9e5a2ad885
affected

2ea086e35c3d726a3bacd0a971c1f02a50e98206 before 529b121b00a6ee3c88fb3c01b443b2b81f686d48
affected

2ea086e35c3d726a3bacd0a971c1f02a50e98206 before 5282491fc49d5614ac6ddcd012e5743eecb6a67c
affected

Default status
affected

5.15
affected

Any version before 5.15
unaffected

5.15.194
unaffected

6.1.154
unaffected

6.6.108
unaffected

6.12.49
unaffected

6.16.9
unaffected

6.17
unaffected

References

git.kernel.org/...c/773fddf976d282ef059c36c575ddb81567acd6bc

git.kernel.org/...c/bdaab5c6538e250a9654127e688ecbbeb6f771d5

git.kernel.org/...c/eb0378dde086363046ed3d7db7f126fc3f76fd70

git.kernel.org/...c/8be498fcbd5b07272f560b45981d4b9e5a2ad885

git.kernel.org/...c/529b121b00a6ee3c88fb3c01b443b2b81f686d48

git.kernel.org/...c/5282491fc49d5614ac6ddcd012e5743eecb6a67c

cve.org (CVE-2025-39943)

nvd.nist.gov (CVE-2025-39943)

Download JSON