{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-26692","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-19T14:20:24.155Z","datePublished":"2024-04-03T14:54:53.343Z","dateUpdated":"2026-08-05T11:26:44.270Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:26:44.270Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Fix regression in writes when non-standard maximum write size negotiated\n\nThe conversion to netfs in the 6.3 kernel caused a regression when\nmaximum write size is set by the server to an unexpected value which is\nnot a multiple of 4096 (similarly if the user overrides the maximum\nwrite size by setting mount parm \"wsize\", but sets it to a value that\nis not a multiple of 4096).  When negotiated write size is not a\nmultiple of 4096 the netfs code can skip the end of the final\npage when doing large sequential writes, causing data corruption.\n\nThis section of code is being rewritten/removed due to a large\nnetfs change, but until that point (ie for the 6.3 kernel until now)\nwe can not support non-standard maximum write sizes.\n\nAdd a warning if a user specifies a wsize on mount that is not\na multiple of 4096 (and round down), also add a change where we\nround down the maximum write size if the server negotiates a value\nthat is not a multiple of 4096 (we also have to check to make sure that\nwe do not round it down to zero)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H","baseScore":8.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The attacker-controlled input is the MaxWriteSize field of the SMB2 NEGOTIATE response received over TCP/445 from a remote SMB server, copied verbatim into server->max_write with no validation. A malicious/compromised server, a DFS-referral target, or an on-path attacker (MaxWriteSize is unsigned in the pre-auth NEGOTIATE and is not covered by FSCTL_VALIDATE_NEGOTIATE_INFO) supplies it purely over the network.\nAC:L - The server simply advertises a MaxWriteSize that is not a multiple of PAGE_SIZE (or zero); there is no race, no dependency on memory layout, and no condition outside the attacker's control. Every large sequential write on the mount then corrupts deterministically.\nPR:N - The attacker is the remote SMB peer and needs no credentials or privileges on the victim client; the poisoned MaxWriteSize is delivered in the NEGOTIATE response, which precedes session setup and authentication entirely.\nUI:R - The victim must mount a CIFS/SMB share from the attacker-controlled or compromised server, since wsize is fixed at mount time in cifs_mount_get_tcon(). This is minimal interaction — an /etc/fstab, autofs, or systemd automount does it with no human present — but a mount action is still required.\nS:U - The corruption and the stuck-writeback hang are confined to the mounting kernel's page cache and the mounted share, within the same security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:L - There is no kernel-memory disclosure, but the skipped tail regions mean in-place rewrites silently fail to overwrite: residual old file content (e.g. secrets a program believed it had replaced) persists on the share and stays readable to anyone with access to the current file. The exposure is bounded to those stale tail regions, so Low rather than High.\nI:H - The remote server fully controls how much of each page is silently discarded — up to 4095 of every 4096 bytes — while write(), close(), and fsync() all report success and the page cache masks the damage until eviction, so backups, databases, config files, and source trees are corrupted undetectably. This is complete, attacker-directed loss of integrity over all data written to the mount.\nA:H - With a server-advertised MaxWriteSize of 0, wsize becomes 0 and wdata->bytes is 0, so all three completion helpers early-return on !len and never undo the unconditional folio_start_writeback(), leaving folios permanently under writeback. That yields unkillable D-state tasks on fsync/sync/truncate/umount, permanently pinned pages, and an ever-growing NR_WRITEBACK that stalls system-wide dirty-page throttling."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/connect.c","fs/smb/client/fs_context.c"],"versions":[{"version":"d08089f649a0cfb2099c8551ac47eef0cc23fdf2","lessThan":"4145ccff546ea868428b3e0fe6818c6261b574a9","status":"affected","versionType":"git"},{"version":"d08089f649a0cfb2099c8551ac47eef0cc23fdf2","lessThan":"63c35afd50e28b49c5b75542045a8c42b696dab9","status":"affected","versionType":"git"},{"version":"d08089f649a0cfb2099c8551ac47eef0cc23fdf2","lessThan":"4860abb91f3d7fbaf8147d54782149bb1fc45892","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/connect.c","fs/smb/client/fs_context.c"],"versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","status":"unaffected","versionType":"semver"},{"version":"6.6.18","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.6","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.6.18"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.7.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4145ccff546ea868428b3e0fe6818c6261b574a9"},{"url":"https://git.kernel.org/stable/c/63c35afd50e28b49c5b75542045a8c42b696dab9"},{"url":"https://git.kernel.org/stable/c/4860abb91f3d7fbaf8147d54782149bb1fc45892"}],"title":"smb: Fix regression in writes when non-standard maximum write size negotiated","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:14:12.775Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/4145ccff546ea868428b3e0fe6818c6261b574a9","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/63c35afd50e28b49c5b75542045a8c42b696dab9","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/4860abb91f3d7fbaf8147d54782149bb1fc45892","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-26692","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T15:53:00.719188Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:33:31.032Z"}}]}}