Executive brief
A vulnerability exists in the Linux kernel's SMB3 client, which is used to connect to network file shares. An attacker could potentially exploit this flaw during the process of mounting a network drive to cause a system crash or access sensitive information from the system's memory. This could lead to a loss of service or unauthorized data exposure on affected Linux systems and certain industrial hardware.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the Linux kernel SMB3 client (cifs.ko) within the parse_server_interfaces() function in fs/smb/client/smb2ops.c. The root cause is a missing bounds check when processing the 'Next' pointer in the network interface information ioctl response; if the pointer exceeds the remaining buffer size, the kernel performs an out-of-bounds access. This can be triggered during a mount operation to a ksmbd server. An attacker can leverage this to cause a kernel panic (DoS) or potentially leak sensitive kernel memory. Patches have been released for various stable kernel branches including 6.1, 6.6, and 6.10+.
Affected products
- Linux Linux Kernel 4.18 to 6.16-rc2
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-08-11: patched: Initial fix committed to Linux kernel tree
- 2025-09-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/7d34ec36abb84fdfb6632a0f2cbda90379ae21fc
- https://git.kernel.org/stable/c/8de33d4d72e8fae3502ec3850bd7b14e7c7328b6
- https://git.kernel.org/stable/c/9bdb8e98a0073c73ab3e6c631ec78877ceb64565
- https://git.kernel.org/stable/c/a0620e1525663edd8c4594f49fb75fe5be4724b0
- https://git.kernel.org/stable/c/a542f93a123555d09c3ce8bc947f7b56ad8e6463
- https://git.kernel.org/stable/c/f6eda5b0e8f8123564c5b34f5801d63243032eac
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html