CVE-2026-89633

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()

coalesce_t2() computes data pointers directly from server-supplied DataOffset fields with no validation against buffer bounds:

data_area_of_tgt = (char *)&pSMBt->hdr.Protocol + get_unaligned_le16(&pSMBt->t2_rsp.DataOffset); data_area_of_src = (char *)&pSMBs->hdr.Protocol + get_unaligned_le16(&pSMBs->t2_rsp.DataOffset); data_area_of_tgt += total_in_tgt; … memcpy(data_area_of_tgt, data_area_of_src, total_in_src);

A small DataOffset can push a pointer below the actual byte area, overwriting header fields; a large one can push it past the buffer end, causing out-of-bounds heap reads (source) or writes (target). The BCC overflow guard does not prevent this: BCC reflects how much data is present, while DataOffset controls where in the buffer it starts.

The "validate target area" comment present since the function was first written in 2005 was a placeholder that was never implemented.

Add lower- and upper-bound checks for both data pointers before the memcpy, and before any target header fields are modified.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxe4eb295d38b57f4d4b956942a48887eb252d97c6 < 672cf86aa6aa0fb4012ce4c3b3498df42ad67a4eaffected
LinuxLinuxe4eb295d38b57f4d4b956942a48887eb252d97c6 < 033bc80019f07d158630df4e69b19a49010f54f1affected
LinuxLinuxe4eb295d38b57f4d4b956942a48887eb252d97c6 < 6343c1da561962688f203362d80d6a3bfa39fa1baffected
LinuxLinux2.6.12affected
LinuxLinux0 < 2.6.12unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References