Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 5 hours ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
smb: client: Fix next buffer leak in receive_encrypted_standard()

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked. Move the MAX_COMPOUND check before allocating next_buffer.

Affected products

Linux
  • <9136a08dc29328edd9867f2545e73906ac9df93b
  • <94e4f672db029414b9888b5137a7559f1febf2d8
  • =<6.18.*
  • <07e0ab81df1790afa35732a4e8e07ff831b29008
  • <1c6267a1d5cf4c73b656f8181b310cbbb3e4767b
  • <4.19
  • <297243e365fc9fe2f8e9b7dd535a65d922cd108b
  • =<5.15.*
  • <927d4805aea0a287d36dd4f826ee24d69a2afee3
  • =<6.12.*
  • =<7.1.*
  • =<6.1.*
  • =<*
  • =<6.6.*
  • <68fc0b6cc03ca58060c0f36454e169f5fe258974
  • <67097772df7791c53d608f04bd31c676ccf79b83
  • ==4.19
  • =<5.10.*