{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89631","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.738Z","datePublished":"2026-09-11T19:45:26.444Z","dateUpdated":"2026-09-13T06:32:09.832Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:32:09.832Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject a tree connect response whose byte count is too small\n\nCIFSTCon() bounds its strnlen() over the byte area with the server's\nByteCount minus two, which for ByteCount 0 or 1 goes negative as an int\nand converts to a huge size_t.  The later subtraction wraps the __u16\nbytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of\nup to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the\nslab object, and the bytes reach userspace through tcon->nativeFileSystem\nin /proc/fs/cifs/DebugData.\n\nReject a byte area too small for what the parser consumes.  Two bytes is\nthe least it can consume, and no conformant response carries fewer.  The\nnew trace point is the 129th smb_eio_trace entry, which __mode(byte)\ncannot represent, so the attribute goes with it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - CIFSTCon() parses a TREE_CONNECT_ANDX response received over TCP (typically port 445) from the SMB peer, so a malicious or compromised CIFS server supplies the undersized ByteCount remotely.\nAC:L - A server that returns success with ByteCount 0 or 1 triggers the integer underflow and wrapped 65535-byte bound deterministically; CONFIG_CIFS_ALLOW_INSECURE_LEGACY defaults to y, and no race or uncontrolled memory layout is required.\nPR:N - The attacker is the remote SMB server (or a MITM on unsigned SMB1); the client authenticates to that peer, so no account, capability, or privilege on the victim host is required.\nUI:N - Existing SMB1 mounts, IPC tcons, automounts, fstab, and cifsroot reconnect via cifs_tree_connect() after a server-induced TCP drop, so the crafted TREE_CONNECT response is processed without contemporaneous user action.\nS:U - The out-of-bounds slab read, kernel-memory leak, and possible oops remain inside the client kernel's security authority and do not cross a VM, IOMMU, or sandbox boundary.\nC:H - ByteCount underflow wraps the __u16 bound to up to 65535 bytes against a ~16KB cifs_request slab, so cifs_strndup_from_utf16() copies adjacent kernel heap into tcon->nativeFileSystem, which is then exposed through /proc/fs/cifs/DebugData.\nI:N - The defect is an out-of-bounds read copied into a newly allocated, correctly sized string; it does not write outside that allocation or provide an arbitrary-write or control-flow primitive.\nA:H - strnlen(), kstrndup(), and cifs_utf16_bytes() walk tens of kilobytes past the cifs_request object into unmapped or guarded pages, causing a kernel oops or panic that a malicious peer can retrigger on reconnect."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/cifssmb.c","fs/smb/client/trace.h"],"versions":[{"version":"cc20c031bb067eb3280a1c4b5c42295093e24863","lessThan":"3be89e8039a85fa3b6cd5f9dcc4c1459eb356c2d","status":"affected","versionType":"git"},{"version":"cc20c031bb067eb3280a1c4b5c42295093e24863","lessThan":"411e484fe71a7f1028de617447edad9cb6d9d68a","status":"affected","versionType":"git"},{"version":"cc20c031bb067eb3280a1c4b5c42295093e24863","lessThan":"65deb18359341141d37dc86fc7853511be3c87a7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/cifssmb.c","fs/smb/client/trace.h"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3be89e8039a85fa3b6cd5f9dcc4c1459eb356c2d"},{"url":"https://git.kernel.org/stable/c/411e484fe71a7f1028de617447edad9cb6d9d68a"},{"url":"https://git.kernel.org/stable/c/65deb18359341141d37dc86fc7853511be3c87a7"}],"title":"smb: client: reject a tree connect response whose byte count is too small","x_generator":{"engine":"bippy-1.2.0"}}}}