CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's SMB client, specifically in the handling of the `ReparseDataLength` field within the `reparse_buf_ptr()` function. An attacker could exploit this flaw to read beyond the allocated buffer, potentially leading to information disclosure or system instability. Organizations using Linux systems, particularly those relying on SMB for file sharing, should prioritize this issue to mitigate potential risks associated with data integrity and security.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() reparse_buf_ptr() reads buf->ReparseDataLength before checking that count covers the full fixed header: buf = (struct reparse_data_buffer *)((u8 *)io + off); len = sizeof(*buf); /* 8 bytes */ rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */ if (count < len || count < rdlen + len) /* check comes after */ struct reparse_data_buffer has ReparseDataLength at offset 4. If a server returns OutputCount < 6, the read at offset 4-5 reaches past the end of the received data. The off+count bounds against iov_len were already validated, but that does not protect against count being smaller than sizeof(*buf). Split the check: verify count >= sizeof(*buf) before reading ReparseDataLength, then verify count covers the data region.