CVE-2026-64257

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject overlapping data areas in SMB2 responses

Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception.

Track data area overlap separately and reject such responses before applying the length compatibility exceptions.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux31c6312608c60b72a1feb99a5afb680645a3e8a3 < 445ece263131780dee273d727a4d6f11934feec7affected
LinuxLinux573e502d14714d2947e22e7eff40ec20a6a44a42 < 36bfa52459e45c0d5b668de2f1c91f6dc5c67775affected
LinuxLinux419ec1b604d7fb60c10aec2dc062371f9fcd4940 < 4a9d2657d3e05f6ed09c148cb127b4e58702275faffected
LinuxLinuxceb875a375dedbf51c9425c1d13a2d7a8435c08c < fdafa1e68dc75045b7b617e6e7d2854950804d83affected
LinuxLinux6e9d10f62773b99bd927940fd9cbdfe7207e23ff < 57cba95f0e97c6f6e45e6731da30aff091bd7460affected
LinuxLinux53b7c271f06be4dd5cfc8c6ef552a8355c891a7f < 8986c932905ea508d66da421eb2eb6e676ace1feaffected
LinuxLinux8d0bbc78046d264bbf6a574ea6f9072258a43e35affected
LinuxLinuxb6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0affected
LinuxLinux5.10.261 < 5.11affected
LinuxLinux5.15.212 < 5.16affected
LinuxLinux7.2-rc3affected
LinuxLinux0 < 7.2-rc3unaffected
LinuxLinux7.2-rc4 <= *unaffected

Weaknesses

References