Linux CIFS filesystem development
 help / color / mirror / Atom feed
From: Greg KH <gregkh@linuxfoundation.org>
To: khj <hj351016@gmail.com>
Cc: CVE Request <CVE-Request@mitre.org>,
	cve@kernel.org, linux-cifs@vger.kernel.org
Subject: Re: CVE-2025-38728: Request to add Bugzilla 218602 as a reference
Date: Wed, 5 Aug 2026 09:45:55 +0200	[thread overview]
Message-ID: <2026080527-sequel-moonscape-0ac0@gregkh> (raw)
In-Reply-To: <CAGr5VtPLAy_N0N4kE5TDndMr3zYukVXDHD49AfToGoa-vMk24A@mail.gmail.com>

On Wed, Aug 05, 2026 at 04:30:15PM +0900, khj wrote:
> Hello Linux Kernel CVE Team,

Did you send this twice?

And no need to bother MITRE for normal CNA stuff that we can easily
handle.

> I would like to request a reference update for CVE-2025-38728.
> 
> I am not requesting a new CVE ID, reassignment, or reporter
> attribution. I am only requesting that the following public Linux
> Kernel Bugzilla report be added to the References section of the CVE
> record:
> 
> https://bugzilla.kernel.org/show_bug.cgi?id=218602
> 
> Bugzilla 218602 was reported on March 15, 2024. It describes the
> missing bounds validation in parse_server_interfaces(), specifically
> that the server-controlled Next value can exceed bytes_left before the
> pointer is advanced and the value is subtracted.
> 
> The fix associated with CVE-2025-38728 adds the corresponding
> validation that rejects a Next value larger than bytes_left:
> 
> https://git.kernel.org/stable/c/7d34ec36abb84fdfb6632a0f2cbda90379ae21fc
> 
> Could you please review whether Bugzilla 218602 can be added as a
> reference to CVE-2025-38728?

It looks like might be the same issue, but it might not be.  We would
need the cifs maintainers to confirm this or not.

If they do confirm it, great, please send us a patch for the vulns.git
repo on git.kernel.org that adds this as a reference for that CVE entry,
as documented in the cve/schema file.

thanks,

greg k-h

      reply	other threads:[~2026-08-05  7:46 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-05  7:30 CVE-2025-38728: Request to add Bugzilla 218602 as a reference khj
2026-08-05  7:45 ` Greg KH [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026080527-sequel-moonscape-0ac0@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=CVE-Request@mitre.org \
    --cc=cve@kernel.org \
    --cc=hj351016@gmail.com \
    --cc=linux-cifs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox