CVE-2026-89632
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
reparse_buf_ptr() reads buf->ReparseDataLength before checking that count covers the full fixed header:
buf = (struct reparse_data_buffer *)((u8 *)io + off);
len = sizeof(*buf); /* 8 bytes */
rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */
if (count < len || count < rdlen + len) /* check comes after */
struct reparse_data_buffer has ReparseDataLength at offset 4. If a server returns OutputCount < 6, the read at offset 4-5 reaches past the end of the received data. The off+count bounds against iov_len were already validated, but that does not protect against count being smaller than sizeof(*buf).
Split the check: verify count >= sizeof(*buf) before reading ReparseDataLength, then verify count covers the data region.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a158bb66b1373866d9fd5997565a58a573085539 < 711cf71300d7992f450600df8864917d3538679f | affected |
| Linux | Linux | a158bb66b1373866d9fd5997565a58a573085539 < 05f78e6cf34ea3a285053bd5999e08e8ac298bd5 | affected |
| Linux | Linux | 6.6.32 < 7.2.4 | affected |
| Linux | Linux | 6.6.32 < 7.3-rc1 | affected |
Weaknesses
References
- https://git.kernel.org/stable/c/711cf71300d7992f450600df8864917d3538679f
- https://git.kernel.org/stable/c/05f78e6cf34ea3a285053bd5999e08e8ac298bd5
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.