{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89633","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.739Z","datePublished":"2026-09-11T19:45:28.083Z","dateUpdated":"2026-09-13T06:32:12.305Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:32:12.305Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()\n\ncoalesce_t2() computes data pointers directly from server-supplied\nDataOffset fields with no validation against buffer bounds:\n\n  data_area_of_tgt = (char *)&pSMBt->hdr.Protocol +\n                     get_unaligned_le16(&pSMBt->t2_rsp.DataOffset);\n  data_area_of_src = (char *)&pSMBs->hdr.Protocol +\n                     get_unaligned_le16(&pSMBs->t2_rsp.DataOffset);\n  data_area_of_tgt += total_in_tgt;\n  ...\n  memcpy(data_area_of_tgt, data_area_of_src, total_in_src);\n\nA small DataOffset can push a pointer below the actual byte area,\noverwriting header fields; a large one can push it past the buffer\nend, causing out-of-bounds heap reads (source) or writes (target).\nThe BCC overflow guard does not prevent this: BCC reflects how much\ndata is present, while DataOffset controls where in the buffer it\nstarts.\n\nThe \"validate target area\" comment present since the function was\nfirst written in 2005 was a placeholder that was never implemented.\n\nAdd lower- and upper-bound checks for both data pointers before the\nmemcpy, and before any target header fields are modified."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - coalesce_t2() runs in cifs_demultiplex_thread on SMB1 TRANS2 responses received over TCP/445; a malicious or compromised SMB1 server (or MITM on an unsigned session) delivers the crafted DataOffset/DataCount fields entirely over the network.\nAC:L - The server fully controls DataOffset, DataCount, and TotalDataCount in both primary and secondary TRANS2 PDUs and can force a large first fragment so mid->resp_buf is set; the unbounded memcpy is deterministic with no race or condition outside the attacker’s control.\nPR:N - The attacker is the remote SMB peer and needs no account or privileges on the victim; coalesce_t2() runs in the demux thread before validate_t2() or any local capability check, and session credentials belong to the client mount, not the attacking server.\nUI:N - Once an SMB1 CIFS mount exists (fstab, autofs, embedded/industrial NAS; CONFIG_CIFS_ALLOW_INSECURE_LEGACY defaults on), reconnect and ordinary lookup/readdir/getattr plus cifs_qfs_tcon QUERY_FS_INFO issue TRANS2 automatically, so the server can trigger coalescing with no further user action.\nS:U - The out-of-bounds heap read/write corrupts the client kernel’s own cifs_request slab within the same host security authority; this is not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - An unvalidated source DataOffset lets memcpy read far past the secondary response (DataOffset is a 16-bit value up to 65535 versus a ~16KB cifs_request object), disclosing adjacent kernel heap; the same memory-corruption primitive can be leveraged for further disclosure.\nI:H - An unvalidated target DataOffset lets memcpy write attacker-controlled bytes past the primary buffer (or backward into the SMB header); the BCC-size guard does not constrain where the copy starts, yielding an out-of-bounds write exploitable for control-flow hijacking.\nA:H - Reading or writing tens of kilobytes past the cifs_request allocation can fault on unmapped pages and oops or panic the demux thread, and a malicious server can retrigger it on every multi-part TRANS2."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb1transport.c"],"versions":[{"version":"e4eb295d38b57f4d4b956942a48887eb252d97c6","lessThan":"672cf86aa6aa0fb4012ce4c3b3498df42ad67a4e","status":"affected","versionType":"git"},{"version":"e4eb295d38b57f4d4b956942a48887eb252d97c6","lessThan":"033bc80019f07d158630df4e69b19a49010f54f1","status":"affected","versionType":"git"},{"version":"e4eb295d38b57f4d4b956942a48887eb252d97c6","lessThan":"6343c1da561962688f203362d80d6a3bfa39fa1b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb1transport.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/672cf86aa6aa0fb4012ce4c3b3498df42ad67a4e"},{"url":"https://git.kernel.org/stable/c/033bc80019f07d158630df4e69b19a49010f54f1"},{"url":"https://git.kernel.org/stable/c/6343c1da561962688f203362d80d6a3bfa39fa1b"}],"title":"smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()","x_generator":{"engine":"bippy-1.2.0"}}}}