Executive brief
A vulnerability exists in the Linux kernel's SMB client, which is used to connect to network file shares. When processing certain malformed file path strings, the system may attempt to read memory outside of the intended boundaries. This could lead to system instability, crashes, or potential unauthorized access to sensitive information stored in memory.
Technical details
An out-of-bounds read vulnerability exists in fs/smb/client/fs_context.c within the cifs_sanitize_prepath function. The root cause is a logic error where the code attempts to access memory at *(cursor2 - 1) before the cursor has been properly advanced, specifically when the input string is empty or consists solely of delimiters (e.g., "/"). An attacker could potentially exploit this via network-delivered path strings to cause a kernel oops/segmentation fault or leak sensitive kernel memory. The issue has been resolved by adding an early exit check that returns NULL if no path content remains after stripping delimiters. Patches are available across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.16.1 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14
Timeline
- 2026-03-30: other: Patch authored by Fredric Cover
- 2026-05-06: disclosed: CVE published
- 2026-05-06: advisory
References
- https://git.kernel.org/stable/c/2d29214448ec0f4e7e18bb1c14dd4a6c07f1c439
- https://git.kernel.org/stable/c/49b1ce6d7cfb6c5a49f68bf5ccfcfb6ba14e63c3
- https://git.kernel.org/stable/c/5d4fe469fe7dbff7d874c196bb680a82f2625d95
- https://git.kernel.org/stable/c/78ec5bf2f589ec7fd8f169394bfeca541b077317
- https://git.kernel.org/stable/c/86f9c23e0814cfdffda9eedf0c591c51ba209010
- https://git.kernel.org/stable/c/a2ba20c17de8eb028f96b1d85f119d3d25655bd9
- https://git.kernel.org/stable/c/fbced33599653471b4581dfe1abc7b467031f126