In the Linux kernel, the following vulnerability has been resolved:
ksmbd: avoid out of bounds access in decode_preauth_ctxt()
Confirm that the accessed pneg_ctxt->HashAlgorithms address sits within the SMB request boundary; deassemble_neg_contexts() only checks that the eight byte smb2_neg_context header + (client controlled) DataLength are within the packet boundary, which is insufficient.
Checking for sizeof(struct smb2_preauth_neg_context) is overkill given that the type currently assumes SMB311_SALT_SIZE bytes of trailing Salt.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Ubuntu | — | Upgrade linux-intel-iotgUpgrade linux-ibm-5.15Upgrade linux-riscv-5.15Upgrade linux-nvidia-tegra-5.15Upgrade linux-lowlatencyUpgrade linux-oracle-5.15Upgrade linux-fipsUpgrade linux-awsUpgrade linux-bluefieldUpgrade linux-aws-5.15Upgrade linux-gcpUpgrade linux-lowlatency-hwe-5.15Upgrade linux-nvidia-tegraUpgrade linux-gkeUpgrade linux-raspiUpgrade linuxUpgrade linux-gcp-fipsUpgrade linux-ibmUpgrade linux-hwe-5.15Upgrade linux-gcp-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-aws-fipsUpgrade linux-azure-5.15Upgrade linux-realtimeUpgrade linux-intel-iot-realtimeUpgrade linux-gkeopUpgrade linux-azure-fde-5.15Upgrade linux-azureUpgrade linux-nvidiaUpgrade linux-xilinx-zynqmpUpgrade linux-nvidia-tegra-igxUpgrade linux-kvmUpgrade linux-oracleUpgrade linux-azure-fips | Jan 6, 2026 | Jan 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub