In the Linux kernel, the following vulnerability has been resolved:
ksmbd: avoid out of bounds access in decode_preauth_ctxt()
Confirm that the accessed pneg_ctxt->HashAlgorithms address sits within the SMB request boundary; deassemble_neg_contexts() only checks that the eight byte smb2_neg_context header + (client controlled) DataLength are within the packet boundary, which is insufficient.
Checking for sizeof(struct smb2_preauth_neg_context) is overkill given that the type currently assumes SMB311_SALT_SIZE bytes of trailing Salt.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Ubuntu | — | Upgrade linux-intel-iot-realtimeUpgrade linux-gkeopUpgrade linux-nvidia-tegra-igxUpgrade linux-gcp-5.15Upgrade linux-azure-fipsUpgrade linux-azure-fde-5.15Upgrade linux-aws-fipsUpgrade linux-ibmUpgrade linux-hwe-5.15Upgrade linux-gcp-fipsUpgrade linux-nvidiaUpgrade linux-realtimeUpgrade linux-xilinx-zynqmpUpgrade linux-azureUpgrade linux-azure-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-kvmUpgrade linux-oracleUpgrade linux-fipsUpgrade linux-raspiUpgrade linux-intel-iotgUpgrade linuxUpgrade linux-oracle-5.15Upgrade linux-gcpUpgrade linux-lowlatencyUpgrade linux-ibm-5.15Upgrade linux-bluefieldUpgrade linux-riscv-5.15Upgrade linux-gkeUpgrade linux-aws-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-nvidia-tegraUpgrade linux-nvidia-tegra-5.15Upgrade linux-aws | Jan 6, 2026 | Jan 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub