CVE-2026-93785
⚪ Do wiadomości
Przepełnienie bufora w jądrze Linux w cifs umożliwia nieprawidłowe interpretowanie danych.
CVSS
0.0
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
In the Linux kernel, the following vulnerability has been resolved: cifs: validate idmap key payload length The cifs.idmap key type stores its payload length in key->datalen, which is limited to U16_MAX. Accepting a larger key payload truncates the recorded length and can make later users interpret the payload using inconsistent bounds. Reject oversized preparsed payloads before allocating or copying them. This keeps key->datalen consistent with the stored data for both inline and separately allocated idmap payloads.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:48 UTC |
Referencje
- https://git.kernel.org/stable/c/125b05ac8ca8758950e4369c1542d57a162f504c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/3a4a34a732e8a08309eed0a74314dbd9f2f1c972 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/455488cd5054bcc59db40fa1cc2c004031a5b2a5 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/6cfeef221ac00d63c07f6122f58e6159bde69ca0 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/8b12f65d7caf16d124098cb4895a203367d35b57 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/945f6cde6bcf8f08f6fa5df8882b1b9582e55efa (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/eeac976b74b4f697cfc517187b7cbfd72652dbbc (416baaa9-dc9f-4396-8d5f-8c081fb06d67)