Feed
Linux Kernel

The kernel SMB server could write past a Kerberos login reply

Brief

This is not the unauthenticated short-packet read already on the site.

Notes

23a0be6a84a3 (Ilan Dudnik) landed via merge 61a09cfc1214 (ksmbd-for-7.3-rc1, Aug 23 08:41 PT). Heap overflow on Kerberos login in a compounded SMB request. The in-kernel SMB server has to be running, and the login path has to be Kerberos. No Fixes line. No Cc:stable.

Not a recast of 153963ac.

Commit 23a0be6a84a38ac169eeab49017934e8e27c65f0

Sources