- EPSS 0.19%
- Veröffentlicht 25.09.2026 10:21:51
- Zuletzt bearbeitet 25.09.2026 11:17:06
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() The SMB1 synchronous read helper CIFSSMBRead() validates the server's DataLength against CIFSMaxBufSize and the caller...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:51
- Zuletzt bearbeitet 03.10.2026 11:18:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.idmap descriptions cifs.idmap key descriptions carry authority-bearing fields (owner and group SIDs and uid/gid values in "os:"/"gs:"/"oi:"/"gi:"...
- EPSS 0.19%
- Veröffentlicht 25.09.2026 10:21:50
- Zuletzt bearbeitet 28.09.2026 06:16:38
In the Linux kernel, the following vulnerability has been resolved: smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid When the administrator mounts with forceuid or forcegid (uid=/gid= mount options), they expect all files to appear...
CVE-2026-97562
- EPSS 0.41%
- Veröffentlicht 25.09.2026 10:21:50
- Zuletzt bearbeitet 03.10.2026 11:18:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: pin DFS superblock in iterator callback tcon_super_cb() stores a raw superblock pointer, but __cifs_get_super() takes its active reference only after iterate_supers_ty...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:49
- Zuletzt bearbeitet 03.10.2026 11:18:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix one-byte OOB read in smb2_parse_native_symlink() When parsing a share-root relative native symlink, memcpy copies smb_target+1 (skipping the leading separator) but...
- EPSS 0.21%
- Veröffentlicht 25.09.2026 10:21:48
- Zuletzt bearbeitet 25.09.2026 15:17:59
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix cifsFileInfo reference leak in deferred close When cifs_close() defers a close, it hands the cifsFileInfo reference of the closing struct file to the queued work. ...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:48
- Zuletzt bearbeitet 03.10.2026 11:18:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: fail DACL rewrite when the new DACL exceeds 64K replace_sids_and_copy_aces() and set_chmod_dacl() accumulate the size of the DACL they build in a u16. That accumulator...
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:21:47
- Zuletzt bearbeitet 03.10.2026 11:18:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid leaking refcount when cifs_sb_tlink() fails cifs_oplock_break() takes over the reference that cifs_queue_oplock_break() acquired when it queued the work, and dro...
CVE-2026-97557
- EPSS 0.6%
- Veröffentlicht 25.09.2026 10:21:47
- Zuletzt bearbeitet 03.10.2026 11:18:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid leaking refcount in cifs_queue_oplock_break() cifs_queue_oplock_break() unconditionally takes a reference on the target file before queueing cifs_oplock_break()....
CVE-2026-97555
- EPSS 0.52%
- Veröffentlicht 25.09.2026 10:21:46
- Zuletzt bearbeitet 03.10.2026 11:18:03
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix heap overflow in DACL owner/group rewrite When id_mode_to_cifs_acl rewrites an existing DACL, it allocates a buffer sized according to the on-disk DACL length repo...