Linux Kernel

•

severity

8.1

published

The Linux kernel's SMB1 client parses length and offset fields from synchronous read responses before confirming that the complete response header was received. A malicious or compromised SMB1 server can return a truncated response that causes the client to read beyond its receive buffer.

CIFSSMBRead() previously dereferenced DataLengthHigh, DataLength, and DataOffset from the server's READ_RSP without first checking rsp_iov.iov_len. If the response was shorter than read_rsp_size, parsing the header itself accessed memory past the end of the received data.

The fix rejects responses smaller than the complete READ_RSP header before accessing those fields. SMB1 is not negotiated by default; the vulnerable path requires an explicit vers=1.0 mount. NVD currently lists the record as received without CVSS metrics, so the score above uses Tenable's assessment.

References

CVSS v3.1

8.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

8.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

8.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

S7t2a9rNtO  lCo5oXkQiMnIg8  aEt9  y1oAu3r4  sSoPfUt0wJa8rUe#  cPr&iBt8i5cGa%lRlByR.Z

request briefing

request briefing

SFtGaTrHtD  lKoLo7kViVn7g6  aEt9  yRoVu%r4  s#oIfGt5w9a&r5e4  c2rFi#t&i8cGa&l$lSy8.P

request briefing

request briefing

S7tCaMrYtL  l3o0oCkXi2nEgN  a9tN  yFo7u2rN  sDo0fCtEwJaVr#e%  cTrIi7t9i0c6a&lBlZy1.X

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026