Back

smb: client: reject short READ responses in CIFSSMBRead()

Published Sep 25, 2026

Description

CIFSSMBRead() reads DataLengthHigh, DataLength and DataOffset out of the READ_RSP returned by the server without first checking that a whole READ_RSP was actually received. The length of the response is recorded in rsp_iov.iov_len, but nothing constrains it to be at least read_rsp_size before those fields are dereferenced.

A malicious or compromised SMB1 server can return a response shorter than the READ_RSP header, so that parsing the header itself reads past the end of the receive buffer. SMB1 is not negotiated by default; reaching this code requires an explicit vers=1.0 mount.

Reject the response unless it is at least read_rsp_size bytes long.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 25, 2026
Updated Sep 25, 2026
Reserved Sep 24, 2026
NVD
Status Received
Modified Sep 25, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Linux
Published Sep 25, 2026
Updated Sep 25, 2026
Exploited since n/a
EUVD-2026-86873