smb: client: reject short READ responses in CIFSSMBRead()
Published Sep 25, 2026
No CVSS score
EPSS 0.20%
Description
CIFSSMBRead() reads DataLengthHigh, DataLength and DataOffset out of the READ_RSP returned by the server without first checking that a whole READ_RSP was actually received. The length of the response is recorded in rsp_iov.iov_len, but nothing constrains it to be at least read_rsp_size before those fields are dereferenced.
A malicious or compromised SMB1 server can return a response shorter than the READ_RSP header, so that parsing the header itself reads past the end of the receive buffer. SMB1 is not negotiated by default; reaching this code requires an explicit vers=1.0 mount.
Reject the response unless it is at least read_rsp_size bytes long.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.12
- Version 6.18.53StatusunaffectedConstraints<=6.18.*
- Version 7.2.7StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc3StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86873 Advisory
- https://git.kernel.org/stable/c/0f1f77b821506a4dacab6ce7d29cf9e0c26f14cd
- https://git.kernel.org/stable/c/aaa221c1b1d288845b55e9c366e5ef608dfff49d
- https://git.kernel.org/stable/c/e6142a8bfc230c7263eb8b0475249c958ce49367
Change history (0)
No recorded changes yet.