CVE-2026-97565

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject short READ responses in CIFSSMBRead()

CIFSSMBRead() reads DataLengthHigh, DataLength and DataOffset out of the READ_RSP returned by the server without first checking that a whole READ_RSP was actually received. The length of the response is recorded in rsp_iov.iov_len, but nothing constrains it to be at least read_rsp_size before those fields are dereferenced.

A malicious or compromised SMB1 server can return a response shorter than the READ_RSP header, so that parsing the header itself reads past the end of the receive buffer. SMB1 is not negotiated by default; reaching this code requires an explicit vers=1.0 mount.

Reject the response unless it is at least read_rsp_size bytes long.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0f1f77b821506a4dacab6ce7d29cf9e0c26f14cdaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < aaa221c1b1d288845b55e9c366e5ef608dfff49daffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e6142a8bfc230c7263eb8b0475249c958ce49367affected
LinuxLinux2.6.12affected
LinuxLinux0 < 2.6.12unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc3 <= *unaffected

Weaknesses

References