{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89632","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.738Z","datePublished":"2026-09-11T19:45:27.325Z","dateUpdated":"2026-09-13T06:32:11.058Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:32:11.058Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()\n\nreparse_buf_ptr() reads buf->ReparseDataLength before checking that\ncount covers the full fixed header:\n\n    buf = (struct reparse_data_buffer *)((u8 *)io + off);\n    len = sizeof(*buf);                          /* 8 bytes */\n    rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */\n\n    if (count < len || count < rdlen + len)      /* check comes after */\n\nstruct reparse_data_buffer has ReparseDataLength at offset 4.  If a\nserver returns OutputCount < 6, the read at offset 4-5 reaches past\nthe end of the received data.  The off+count bounds against iov_len\nwere already validated, but that does not protect against count being\nsmaller than sizeof(*buf).\n\nSplit the check: verify count >= sizeof(*buf) before reading\nReparseDataLength, then verify count covers the data region."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The flaw is in the in-kernel SMB client parser for FSCTL_GET_REPARSE_POINT IOCTL replies on TCP/445. A malicious, compromised, or on-path SMB server reaches reparse_buf_ptr() with crafted OutputOffset/OutputCount; this matches sibling client response-parsing scores such as CVE-2026-46155 and CVE-2024-49996.\nAC:L - The server fully controls OutputOffset and OutputCount. A successful IOCTL PDU with OutputCount < 6 and OutputOffset near iov_len (for example a 448-byte cifs_small_rq-sized frame) deterministically loads ReparseDataLength past the received payload, with no race or attacker-uncontrollable layout.\nPR:N - The attacker is the remote SMB server (or a MITM on an unsigned session) and needs no account, credentials, or capabilities on the victim client. GET_REPARSE runs on an already established tree connect after ordinary CREATE/lookup; the client authenticates to the server, not the reverse.\nUI:N - On an already-mounted or automounted CIFS share, any routine lookup/stat of a reparse point — including files the server flags as reparse in CREATE — issues FSCTL_GET_REPARSE_POINT. Backup jobs, indexers, and inode revalidation hit the parser with no contemporaneous victim mount action.\nS:U - The two-byte out-of-bounds load and any resulting oops stay inside the client kernel's security authority. The bug does not cross a VM, IOMMU, or sandbox boundary.\nC:L - The use-before-check reads exactly two bytes of ReparseDataLength past the IOCTL output region (and, when the PDU fills cifs_small_rq, past that 448-byte slab). Those bytes are passed only to smb_EIO2 tracing, so disclosure is strictly bounded, matching CVE-2026-64448 rather than unbounded heap leaks.\nI:N - The out-of-bounds access is a u16 load used only in the subsequent length check and error trace. On failure the helper returns -EIO and does not install a reparse tag or copy payload, so there is no kernel write or metadata-corruption primitive.\nA:H - A PDU that fills the cifs_small_rq or cifs_request slab with OutputOffset at the object end makes the two-byte load a true slab-out-of-bounds access, which KASAN reports as a BUG and which can oops/panic if the next page is unmapped. A malicious server can retrigger it on every GET_REPARSE."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2inode.c"],"versions":[{"version":"a158bb66b1373866d9fd5997565a58a573085539","lessThan":"711cf71300d7992f450600df8864917d3538679f","status":"affected","versionType":"git"},{"version":"a158bb66b1373866d9fd5997565a58a573085539","lessThan":"05f78e6cf34ea3a285053bd5999e08e8ac298bd5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2inode.c"],"versions":[{"version":"6.6.32","lessThan":"7.2.4","status":"affected","versionType":"semver"},{"version":"6.6.32","lessThan":"7.3-rc1","status":"affected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.32","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.32","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/711cf71300d7992f450600df8864917d3538679f"},{"url":"https://git.kernel.org/stable/c/05f78e6cf34ea3a285053bd5999e08e8ac298bd5"}],"title":"smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()","x_generator":{"engine":"bippy-1.2.0"}}}}