Junglewise Threat Intelligence

CVE-2026-43362: Linux Kernel SMB client data corruption in SMB2_write

CVE-2026-43362 · Severity: high · CVSS 8.1 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SMB client can lead to data corruption when writing files to network shares. When a network connection is unstable and a write operation needs to be retried, the system may accidentally send encrypted data as if it were plain text, corrupting the file on the server. This affects various file operations including creating special files and symbolic links on network storage.

Technical details

A vulnerability in the Linux kernel SMB client's SMB2_write() function causes in-place encryption corruption. The function smb3_init_transform_rq() shares a pointer to the request I/O vector (rq_iov), allowing crypt_message() to encrypt the payload in-place. If a replayable error occurs (such as a connection drop), the subsequent retry sends the already-encrypted ciphertext as if it were plaintext, resulting in data corruption on the remote share. This issue primarily affects sync writes in kernels prior to 6.10 and specific operations like SFU mknod and MF symlinks. The fix involves moving the write payload into rq_iter via iov_iter_kvec() to ensure a deep copy is made before encryption.

Affected products

  • Linux Linux Kernel 6.3 to 6.10 (sync writes)

Timeline

  • 2026-03-09: other: Patch authored
  • 2026-05-08: disclosed: CVE published
  • 2026-05-08: advisory

References

Related threats