Executive brief
The Linux kernel's SMB (Server Message Block) client implementation contains a buffer overflow vulnerability in its tree connect response parser. When a malicious or malformed SMB server sends a tree connect response with an abnormally small byte count, the kernel's CIFSTCon function miscalculates buffer boundaries, allowing attackers to read sensitive kernel memory and expose it to userspace. This could leak authentication tokens, file paths, and other confidential information handled by the SMB client.
Technical details
The vulnerability exists in the CIFSTCon() function (fs/smb/client/cifssmb.c) where a ByteCount value of 0 or 1 causes integer underflow when subtracted from for use in strnlen() bounds calculation. The underflowed value converts to a very large size_t, which then wraps a __u16 bytes_left variable, allowing subsequent cifs_strndup_from_utf16() calls to read up to 65535 bytes from a ~16 KB slab-allocated cifs_req_poolp object, overflowing into adjacent kernel memory. The leaked data is exposed through tcon->nativeFileSystem in /proc/fs/cifs/DebugData. The attack requires a network-reachable SMB server (or MITM position) capable of sending malformed responses. A patch adds validation to reject tree connect responses with ByteCount less than 2, the minimum required by the SMB specification.
Affected products
- Linux Linux kernel 2.6.11 through 6.18+ (all versions with SMB client support)
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Fix merged in stable kernel tree; upstream commit 65deb18359341141d37dc86fc7853511be3c87a7