
CVE-2026-97565
Linux Kernel
•
severity
published
The Linux kernel's SMB1 client parses length and offset fields from synchronous read responses before confirming that the complete response header was received. A malicious or compromised SMB1 server can return a truncated response that causes the client to read beyond its receive buffer.
CIFSSMBRead() previously dereferenced DataLengthHigh, DataLength, and DataOffset from the server's READ_RSP without first checking rsp_iov.iov_len. If the response was shorter than read_rsp_size, parsing the header itself accessed memory past the end of the received data.
The fix rejects responses smaller than the complete READ_RSP header before accessing those fields. SMB1 is not negotiated by default; the vulnerable path requires an explicit vers=1.0 mount. NVD currently lists the record as received without CVSS metrics, so the score above uses Tenable's assessment.
References
Explore our other findings
