Executive brief
The Linux kernel's SMB client implementation contains a vulnerability in how it processes multi-part server responses. A malicious or compromised SMB server can send specially crafted responses that cause the kernel to read from or write to memory outside the intended buffer, potentially corrupting kernel data structures or leaking sensitive information. This affects systems that use SMB/CIFS to connect to file servers.
Technical details
The vulnerability exists in the coalesce_t2() function in fs/smb/client/smb1transport.c, which reassembles fragmented SMB Transaction2 responses. The function computes data pointers from server-supplied DataOffset fields without validating them against buffer boundaries. A small DataOffset value can cause pointers to reference memory below the actual buffer (enabling header field overwrites), while a large value can push pointers past the buffer end (causing out-of-bounds heap reads or writes). The existing BCC (Byte Count) overflow check cannot prevent this because BCC indicates data size, not location. The fix adds lower- and upper-bound validation for both source and target data pointers before performing the memcpy operation. Network reachability to an SMB server is required; no authentication or local access is needed.
Affected products
- Linux Linux kernel 2.6.11 and later (extensively)
Timeline
- 2026-09-11: disclosed: Published on NVD
- 2026-08-24: patched: Patch merged upstream (commit 6343c1da561962688f203362d80d6a3bfa39fa1b)
- 2026-09-07: other: Backported to stable trees