Executive brief
A vulnerability in the Linux kernel's SMB client could allow a malicious or compromised server to read sensitive information from the client's memory. This occurs when the client processes a specially crafted response from a file server. An exploit could lead to the leakage of adjacent kernel memory, potentially exposing credentials or other private data.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel SMB client (cifs.ko) within the smb2_compound_op() function. The root cause is a failure in check_wsl_eas() to validate that the OutputBufferLength provided by the server fits within the actual allocated buffer (iov_len) when an Extended Attribute (EA) list is terminated early. A malicious server can send a truncated response with a large OutputBufferLength, causing a subsequent memcpy() to read beyond the end of the rsp_iov allocation. This can result in the leakage of adjacent kernel heap memory to the attacker. The issue has been resolved by adding proper bounds checking against the iov_len in the check_wsl_eas() function.
Affected products
- Linux Linux Kernel Fixed in versions 512d33b, 8d09328, 9b3af35, a16f70a, dffb44b
Timeline
- 2026-05-06: other: Patch authored
- 2026-05-28: advisory: CVE published
References
- https://git.kernel.org/stable/c/512d33bc8ea4ea5c19728ee118715f4b1f4d1926
- https://git.kernel.org/stable/c/8d09328dfda089675e4c049f3f256064a1d1996b
- https://git.kernel.org/stable/c/9b3af35645ff9cd334edc130249f9a2fb2bea25f
- https://git.kernel.org/stable/c/a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c
- https://git.kernel.org/stable/c/dffb44b2e06a2908e249f0f93156fc987eee1d1c