Executive brief
A vulnerability exists in the Linux kernel's SMB client, which is used to connect to network file shares. An attacker could potentially exploit this to cause a system crash or gain unauthorized access to data by sending specially crafted network packets. This affects systems using SMB Direct (RDMA) for high-performance file transfers.
Technical details
A vulnerability in the Linux kernel SMB client (specifically in fs/smb/client/smbdirect.c) stems from a lack of validation for data_offset, data_length, and remaining_data_length fields in SMB Direct data transfer packets. In the recv_done function, the kernel failed to verify that these fields were within the bounds of the received buffer (wc->byte_len) or the configured maximum fragment size. An attacker could provide malicious offsets or lengths to trigger out-of-bounds access or memory corruption. The fix introduces strict bounds checking against the actual received byte length and the socket's max_fragmented_recv_size. This issue primarily affects SMB over RDMA connections.
Affected products
- Linux Linux Kernel 4.16 to 6.16.9
Timeline
- 2025-10-04: disclosed
- 2025-10-04: advisory
- 2025-09-25: patched: Patch committed to stable tree.