Executive brief
A vulnerability in the Linux kernel's SMB client could allow a malicious or non-conforming server to cause the client to read beyond its allocated memory buffers. This occurs when the client incorrectly processes certain network responses during the initial connection setup. While primarily resulting in a system crash or information leakage from memory, it could impact the stability and security of systems mounting remote file shares.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel SMB client (CIFS) within the smb2_check_message() function. The root cause is a legacy 'quirk' that unconditionally accepts SMB2 responses where the calculated length is one byte larger than the actual received bytes (intended to handle implied bcc[0] padding). When a response contains a data area, this +1 exemption allows the reported data length to exceed the receive buffer. An attacker-controlled or non-conforming SMB server can trigger this during the NEGOTIATE or SESSION_SETUP phases, leading to out-of-bounds reads in the SPNEGO/negTokenInit or NTLMSSP challenge decoders. The issue has been addressed by restricting the length exemption to responses that do not carry a data area.
Affected products
- Linux Linux Kernel 7.1.0-rc6
Timeline
- 2026-07-07: disclosed: Vulnerability reported and patch authored
- 2026-07-24: patched: Patch committed to stable tree
- 2026-07-25: advisory: CVE-2026-64448 published
References
- https://git.kernel.org/stable/c/31c6312608c60b72a1feb99a5afb680645a3e8a3
- https://git.kernel.org/stable/c/419ec1b604d7fb60c10aec2dc062371f9fcd4940
- https://git.kernel.org/stable/c/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f
- https://git.kernel.org/stable/c/573e502d14714d2947e22e7eff40ec20a6a44a42
- https://git.kernel.org/stable/c/6e9d10f62773b99bd927940fd9cbdfe7207e23ff
- https://git.kernel.org/stable/c/8d0bbc78046d264bbf6a574ea6f9072258a43e35
- https://git.kernel.org/stable/c/b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0