Re: CVE-2025-38728: Request to add Bugzilla 218602 as a reference

Greg KH <[email protected]>
Newsgroups org.kernel.vger.linux-cifs
Message-ID <2026080527-sequel-moonscape-0ac0@gregkh>
On Wed, Aug 05, 2026 at 04:30:15PM +0900, khj wrote:
> Hello Linux Kernel CVE Team,

Did you send this twice?

And no need to bother MITRE for normal CNA stuff that we can easily
handle.

> I would like to request a reference update for CVE-2025-38728.
> 
> I am not requesting a new CVE ID, reassignment, or reporter
> attribution. I am only requesting that the following public Linux
> Kernel Bugzilla report be added to the References section of the CVE
> record:
> 
> https://bugzilla.kernel.org/show_bug.cgi?id=218602
> 
> Bugzilla 218602 was reported on March 15, 2024. It describes the
> missing bounds validation in parse_server_interfaces(), specifically
> that the server-controlled Next value can exceed bytes_left before the
> pointer is advanced and the value is subtracted.
> 
> The fix associated with CVE-2025-38728 adds the corresponding
> validation that rejects a Next value larger than bytes_left:
> 
> https://git.kernel.org/stable/c/7d34ec36abb84fdfb6632a0f2cbda90379ae21fc
> 
> Could you please review whether Bugzilla 218602 can be added as a
> reference to CVE-2025-38728?

It looks like might be the same issue, but it might not be.  We would
need the cifs maintainers to confirm this or not.

If they do confirm it, great, please send us a patch for the vulns.git
repo on git.kernel.org that adds this as a reference for that CVE entry,
as documented in the cve/schema file.

thanks,

greg k-h
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.