Linux Kernel

•

severity

7.3

published

The Linux kernel's SMB1 client fails to validate a server-supplied data offset before copying a synchronous read response. A malicious or compromised SMB1 server can make the client read beyond the received response buffer, potentially disclosing adjacent kernel heap data or crashing the system.

CIFSSMBRead() validates DataLength against the maximum CIFS buffer size and the caller's requested count, but previously did not ensure that the complete [DataOffset, DataOffset + DataLength) range lay within the response actually received. A large DataOffset could therefore move the source pointer past the end of the response while leaving DataLength apparently valid.

The fix rejects responses whose data range does not fit within rsp_iov.iov_len, using overflow-safe arithmetic before forming the copy source. SMB1 is not negotiated by default; the vulnerable path requires an explicit vers=1.0 mount. NVD currently lists the record as received without CVSS metrics, so the score above uses Tenable's assessment.

References

CVSS v3.1

7.3

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

7.3

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

7.3

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

S$tJa#rZtA  l%oMo7kSiBn0g@  aXt#  yWo#uHrA  sOo8f6t1wCaPrXe3  c5r4iQt&i5c$a1l2l8y7.%

request briefing

request briefing

SJt8a8r&t5  l$o1oGkUiZnHgH  aFtE  yZoJuIrL  sToEfOt%wMaWrSeV  cYrMi3tQiTc3aYl2lRyP.E

request briefing

request briefing

S5tBaIrGtC  lKoWoMk3i7n4gH  aRtU  yPoHu7r6  sSoOfUtBw8aYrLeI  cFrMi2t5i1c1a8lPl9y2.6

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026