CVE-2026-64257
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
30/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
smb: client: reject overlapping data areas in SMB2 responses<br />
<br />
Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to<br />
responses without data area") restricted the implied bcc[0] length<br />
exception to responses without a data area. However, the overlap<br />
handling in __smb2_calc_size() clears data_length, which can make an<br />
invalid response appear to have no data area and so qualify for the<br />
exception.<br />
<br />
Track data area overlap separately and reject such responses before<br />
applying the length compatibility exceptions.
Impacto
Puntuación base 3.x
9.10
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/36bfa52459e45c0d5b668de2f1c91f6dc5c67775
- https://git.kernel.org/stable/c/445ece263131780dee273d727a4d6f11934feec7
- https://git.kernel.org/stable/c/4a9d2657d3e05f6ed09c148cb127b4e58702275f
- https://git.kernel.org/stable/c/57cba95f0e97c6f6e45e6731da30aff091bd7460
- https://git.kernel.org/stable/c/8986c932905ea508d66da421eb2eb6e676ace1fe
- https://git.kernel.org/stable/c/fdafa1e68dc75045b7b617e6e7d2854950804d83



