Junglewise Threat Intelligence

CVE-2026-89637: Linux kernel CIFS use-after-free in cifs_check_trans2()

CVE-2026-89637 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SMB client (CIFS) contains a use-after-free vulnerability in its handling of malformed SMB TRANSACT2 responses. When a server sends a series of incomplete or malformed multi-part responses, the kernel may reuse freed memory buffers, allowing a remote attacker to trigger memory corruption and potentially achieve code execution. This affects systems that mount CIFS shares from untrusted or compromised SMB servers.

Technical details

The vulnerability is a use-after-free (UAF) combined with a buffer leak in the cifs_check_trans2() function in fs/smb/client/smb1transport.c. When a valid primary TRANSACT2 response is received and a subsequent secondary response is malformed or fails validation, handle_mid() overwrites mid->resp_buf with the new buffer without properly freeing the old one, while also failing to clear server->smallbuf/bigbuf pointers. Later, when the user thread frees mid->resp_buf, the demux thread reuses the dangling server buffer pointers for the next packet, causing UAF. The fix combines early-exit conditions and, when mid->multiRsp is already set, aborts the transaction inline by setting multiEnd, calling dequeue_mid() with malformed=true, and returning true to prevent handle_mid() from touching the buffers. The vulnerability requires network connectivity to an SMB server and can be triggered by a malicious or compromised server.

Affected products

  • Linux Linux kernel all versions with CIFS support; fix backported to stable branches including 4.4.y through 7.2.y

Timeline

  • 2026-09-11: disclosed: Public disclosure via NVD
  • 2026-08-24: patched: Fix committed upstream by Paulo Alcantara
  • 2026-09-07: patched: Fix backported to stable kernel trees by Greg Kroah-Hartman

References

Related threats