Executive brief
A vulnerability was identified in the Linux kernel's SMB client, which is used to connect to network file shares. Under specific error conditions when opening a file, the system could experience a crash or memory corruption due to improper handling of internal data buffers. This could lead to system instability or a denial-of-service for affected Linux systems.
Technical details
A use-after-free (UAF) and double-free vulnerability exists in the Linux kernel SMB client within 'fs/smb/client/smb2file.c'. The issue occurs in 'smb2_open_file()' when an initial 'SMB2_open' call fails with '-EACCES' and the client attempts a retry without 'FILE_READ_ATTRIBUTES'. If the error response buffer is freed but the '@err_iov' and '@err_buftype' variables are not cleared before the retry, subsequent error handling or retries can reference or free the same memory address again. This is resolved by zeroing out these variables using 'memset' and setting the buffer type to 'CIFS_NO_BUFFER' before the second 'SMB2_open' call.
Affected products
- Linux Linux kernel v6.1, v6.6, v6.7, v6.8
Timeline
- 2026-02-05: other: Vulnerability fixed in kernel source
- 2026-05-27: advisory: CVE-2026-45972 published by NVD
References
- https://git.kernel.org/stable/c/4d339b219004869e96c4ce56b8891f83a38da4c0
- https://git.kernel.org/stable/c/639deb962986ef2f5e2a6d5a600c66f922471e81
- https://git.kernel.org/stable/c/7425453ea16dbc3bbb0f6cac4d60b537e5e4d151
- https://git.kernel.org/stable/c/96e53bb3ee2f354cf6b4ab07bcc56e500f8b3f74
- https://git.kernel.org/stable/c/e66dcf7bb9c4df5582c82bc3582725abcbfbea73
- https://git.kernel.org/stable/c/ebbbc4bfad4cb355d17c671223d0814ee3ef4eda