Executive brief
A vulnerability exists in the Linux kernel's ksmbd component, which provides SMB file-sharing services. An attacker could exploit this flaw to cause memory corruption or a system crash by sending specifically crafted file requests. This could lead to unauthorized access to sensitive information or a complete disruption of the file-sharing service.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the ksmbd SMB server within the Linux kernel. The flaw occurs in the get_file_all_info() function when handling compound requests (specifically QUERY_DIRECTORY followed by QUERY_INFO). If the first command in the compound request consumes most of the available transaction buffer, the subsequent call to smbConvertToUTF16() fails to validate the remaining buffer space against the filename length. An attacker with network access and basic user privileges can trigger this by providing a large OutputBufferLength, leading to a buffer overflow beyond the response buffer. This can result in memory corruption, kernel instability, or potential code execution. Patches have been released for various stable kernel branches including 5.15, 6.1, 6.6, 6.12, 6.18, and 6.19.
Affected products
- Linux Linux Kernel 5.15.145 to 5.15.203, 6.1.71 to 6.1.168, 6.6 to 6.6.131, 6.7 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11
Timeline
- 2026-03-19: other: Initial patch authored
- 2026-04-22: disclosed: CVE published
- 2026-04-22: patched: Patches integrated into stable kernel trees
References
- https://git.kernel.org/stable/c/358cdaa1f7fbf2712cb4c5f6b59cb9a5c673c5fe
- https://git.kernel.org/stable/c/3a852f9d1c981fb14f6bf4e24999e0ea8088a7d7
- https://git.kernel.org/stable/c/4cca3eff2099b18672934a39cee70aed835d652c
- https://git.kernel.org/stable/c/7aec5a769d2356cbf344d85bcfd36de592ac96a5
- https://git.kernel.org/stable/c/9d7032851d6f5adbe2739601ca456c0ad3b422f0
- https://git.kernel.org/stable/c/b0cd9725fe2bcc9f37d096b132318a9060373f5d
- https://git.kernel.org/stable/c/beef2634f81f1c086208191f7228bce1d366493d