In the Linux kernel, the following vulnerability has been resolved:
cifs: parsedfsreferrals: prevent oob on malformed input
Malicious SMB server can send invalid reply to FSCTLDFSGET_REFERRALS
Processing of such replies will cause oob.
Return -EINVAL error on such replies to prevent oob-s.