In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size This is inspired by the check for data_offset + data_length.
https://git.kernel.org/stable/c/e1868ba37fd27c6a68e31565402b154beaa65df0
https://git.kernel.org/stable/c/d3cb3f209d35c44b7ee74f77ed27ebb28995b9ce
https://git.kernel.org/stable/c/c64b915bb3d9339adcae5db4be2c35ffbef5e615
https://git.kernel.org/stable/c/9644798294c7287e65a7b26e35aa6d2ce3345bcc
https://git.kernel.org/stable/c/196a3a7676d726ee67621ea2bf3b7815ac2685b4