Executive brief
The Linux kernel's ksmbd (SMB server) component contains a memory safety vulnerability where it reads beyond allocated buffer boundaries when processing authentication responses from a mount daemon. A malicious or compromised authentication service can trigger this flaw to read sensitive kernel memory, potentially exposing credentials or other confidential data.
Technical details
The vulnerability is a slab-out-of-bounds read in ksmbd_alloc_user() caused by insufficient validation of the hash_sz field in IPC login responses. The resp->hash_sz parameter (a user-controlled __u16, range 0–65535) is used directly as the size argument to memcpy() without checking against the fixed KSMBD_REQ_MAX_HASH_SZ limit of the resp->hash[] buffer. An attacker who can send a malformed IPC login response (via local access to the mount daemon interface) can cause memcpy() to read up to 65535 bytes past the hash buffer, leaking kernel memory. The fix adds validation to reject responses where hash_sz exceeds the on-stack buffer size before the copy occurs. The vulnerability is reachable via the SMB authentication code path and requires ability to send crafted IPC messages to ksmbd.
Affected products
- Linux Linux kernel 7.1.0 and likely others
Timeline
- 2026-09-17: disclosed