In the Linux kernel, the following vulnerability has been resolved:ksmbd: validate command request sizeIn commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), exceptfor SMB2_OPLOCK_BREAK_HE command, the request size of other commandsis not checked, it's not expected. Fix it by add check for requestsize of other commands.
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds