CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's SMB client, specifically within the `cifs_check_trans2()` function, which can lead to a use-after-free condition due to improper handling of malformed secondary TRANSACT2 responses. This flaw can result in memory corruption, potentially allowing an attacker to execute arbitrary code or crash the system. Organizations using Linux systems that rely on SMB for file sharing should prioritize patching this vulnerability to mitigate risks associated with memory management issues.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid->resp_buf with the new buffer (leaking the primary buffer) and, because mid->multiRsp is set, skips the server->smallbuf/bigbuf NULL-out. When the user thread frees mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid->multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid->resp_buf or the server buffer pointers.