In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix wrong index reference in smb2_compound_op()
In smb2_compound_op(), the loop that processes each command's response uses wrong indices when accessing response bufferes.
This incorrect indexing leads to improper handling of command results. Also, if incorrectly computed index is greather than or equal to MAX_COMPOUND, it can cause out-of-bounds accesses.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.12-modules-extraUpgrade kernel6.12-debuginfo-common-aarch64Upgrade kernel6.12-libbpfUpgrade kernel6.12-tools-develUpgrade kernel6.12-libbpf-debuginfoUpgrade kernel6.12-modules-extra-commonUpgrade kernel6.12-libbpf-staticUpgrade kernel6.12-libbpf-develUpgrade bpftool6.12-debuginfoUpgrade bpftool6.12Upgrade kernel-livepatch-6.12.53-69.119Upgrade perf6.12-debuginfoUpgrade kernel6.12Upgrade kernel6.12-debuginfo-common-x86_64Upgrade kernel6.12-tools-debuginfoUpgrade kernel6.12-headersUpgrade kernel6.12-develUpgrade python3-perf6.12-debuginfoUpgrade kernel6.12-debuginfoUpgrade python3-perf6.12Upgrade perf6.12Upgrade kernel6.12-tools | Dec 9, 2025 | Oct 15, 2025 |
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 15, 2025 |
| Ubuntu | — | Upgrade linux-oracleUpgrade linux-azureUpgrade linux-raspiUpgrade linux-riscvUpgrade linux-awsUpgrade linux-realtimeUpgrade linux-gcpUpgrade linux | Oct 30, 2025 | Oct 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub