
CVE-2026-97563
Linux Kernel
•
severity
published
The Linux kernel's SMB1 client fails to validate a server-supplied data offset before copying a synchronous read response. A malicious or compromised SMB1 server can make the client read beyond the received response buffer, potentially disclosing adjacent kernel heap data or crashing the system.
CIFSSMBRead() validates DataLength against the maximum CIFS buffer size and the caller's requested count, but previously did not ensure that the complete [DataOffset, DataOffset + DataLength) range lay within the response actually received. A large DataOffset could therefore move the source pointer past the end of the response while leaving DataLength apparently valid.
The fix rejects responses whose data range does not fit within rsp_iov.iov_len, using overflow-safe arithmetic before forming the copy source. SMB1 is not negotiated by default; the vulnerable path requires an explicit vers=1.0 mount. NVD currently lists the record as received without CVSS metrics, so the score above uses Tenable's assessment.
References
Explore our other findings
