6 min read
SMBGhost & SMBleed: Analysis of CVE-2020-0796 + CVE-2020-1206
Analysis of an Integer Overflow (SMBGhost) and an uninitialized kernel memory leak (SMBleed) in the SMBv3.1.1 decompression routine, and a Pre-Auth RCE achieved by chaining the two bugs
Read full article