Executive brief
The Linux kernel's SMB client (CIFS) contains a use-after-free vulnerability in its handling of malformed SMB TRANSACT2 responses. When a server sends a series of incomplete or malformed multi-part responses, the kernel may reuse freed memory buffers, allowing a remote attacker to trigger memory corruption and potentially achieve code execution. This affects systems that mount CIFS shares from untrusted or compromised SMB servers.
Technical details
The vulnerability is a use-after-free (UAF) combined with a buffer leak in the cifs_check_trans2() function in fs/smb/client/smb1transport.c. When a valid primary TRANSACT2 response is received and a subsequent secondary response is malformed or fails validation, handle_mid() overwrites mid->resp_buf with the new buffer without properly freeing the old one, while also failing to clear server->smallbuf/bigbuf pointers. Later, when the user thread frees mid->resp_buf, the demux thread reuses the dangling server buffer pointers for the next packet, causing UAF. The fix combines early-exit conditions and, when mid->multiRsp is already set, aborts the transaction inline by setting multiEnd, calling dequeue_mid() with malformed=true, and returning true to prevent handle_mid() from touching the buffers. The vulnerability requires network connectivity to an SMB server and can be triggered by a malicious or compromised server.
Affected products
- Linux Linux kernel all versions with CIFS support; fix backported to stable branches including 4.4.y through 7.2.y
Timeline
- 2026-09-11: disclosed: Public disclosure via NVD
- 2026-08-24: patched: Fix committed upstream by Paulo Alcantara
- 2026-09-07: patched: Fix backported to stable kernel trees by Greg Kroah-Hartman