Junglewise Threat Intelligence

CVE-2026-64257: Linux Kernel SMB client validation bypass in SMB2 responses

CVE-2026-64257 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SMB client could allow a malicious or compromised server to send specially crafted responses that bypass security checks. This occurs when the client incorrectly processes overlapping data areas in network messages, potentially leading to memory corruption or system instability. Users should update their Linux kernel to a patched version to ensure secure communication with file servers.

Technical details

A vulnerability exists in the Linux kernel SMB client's handling of SMB2 responses. Specifically, the function `__smb2_calc_size()` in `fs/smb/client/smb2misc.c` clears the `data_length` field when it detects an overlap between the data area and the fixed header. This behavior can cause an invalid response to be incorrectly identified as having no data area, allowing it to bypass length compatibility exceptions introduced in previous commits. An attacker controlling a malicious SMB server could exploit this to send malformed responses that the client fails to reject. The fix involves tracking data area overlaps separately and explicitly rejecting such responses before applying length exceptions.

Affected products

  • Linux Linux Kernel 5.10.261, 5.15.212, 7.2-rc3

Timeline

  • 2026-07-25: disclosed: Initial publication of the vulnerability details.
  • 2026-07-25: advisory: NVD published the CVE record.

References

Related threats