In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix the error length of VALIDATE_NEGOTIATE_INFO message
Commit d5c7076b772a ("smb3: add smb3.1.1 to default dialect list") extend the dialects from 3 to 4, but forget to decrease the extended length when specific the dialect, then the message length is larger than expected.
This maybe leak some info through network because not initialize the message body.
After apply this patch, the VALIDATE_NEGOTIATE_INFO message length is reduced from 28 bytes to 26 bytes.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernelUpgrade perf-debuginfoUpgrade kernel-headersUpgrade kernel-debuginfoUpgrade bpftool-debuginfoUpgrade python-perf-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-tools-develUpgrade kernel-livepatch-5.15.75-48.135Upgrade perfUpgrade kernel-toolsUpgrade bpftoolUpgrade python-perfUpgrade kernel-livepatch-5.10.155-138.670Upgrade kernel-debuginfo-common-aarch64Upgrade kernel-devel | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-tools-libsUpgrade kernel-toolsUpgrade python3-perfUpgrade bpftoolUpgrade kernel-abi-stablelistsUpgrade kernel | Mar 10, 2026 | Mar 10, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 30, 2025 |
| Ubuntu | — | Upgrade linux-gcp-fipsUpgrade linux-aws-5.4Upgrade linux-ibm-5.4Upgrade linux-hwe-5.15Upgrade linux-azureUpgrade linux-intel-iotg-5.15Upgrade linux-aws-5.15Upgrade linux-raspiUpgrade linuxUpgrade linux-azure-5.4Upgrade linux-gkeopUpgrade linux-lowlatencyUpgrade linux-azure-fipsUpgrade linux-aws-fipsUpgrade linux-awsUpgrade linux-ibmUpgrade linux-iotUpgrade linux-hwe-5.4Upgrade linux-gcpUpgrade linux-gcp-5.4Upgrade linux-bluefieldUpgrade linux-gkeUpgrade linux-intel-iotgUpgrade linux-oracleUpgrade linux-nvidiaUpgrade linux-fipsUpgrade linux-gcp-5.15Upgrade linux-oracle-5.15Upgrade linux-realtimeUpgrade linux-raspi-5.4Upgrade linux-azure-5.15Upgrade linux-oracle-5.4Upgrade linux-riscv-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-kvmUpgrade linux-xilinx-zynqmp | Jan 6, 2026 | Jan 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Dec 30, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub