{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89637","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.739Z","datePublished":"2026-09-11T19:45:31.048Z","dateUpdated":"2026-09-13T06:32:16.928Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:32:16.928Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2\n\nWhen a valid primary TRANSACT2 response has been received (mid->resp_buf\nset, mid->multiRsp true) and a subsequent secondary response causes\ncifs_check_trans2() to return false -- either because the SMB header is\ninvalid (malformed != 0) or because check2ndT2() rejects the PDU --\nhandle_mid() overwrites mid->resp_buf with the new buffer (leaking the\nprimary buffer) and, because mid->multiRsp is set, skips the\nserver->smallbuf/bigbuf NULL-out.  When the user thread frees\nmid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the\ndemux thread reuses it for the next packet, resulting in a use-after-free.\n\nCombine both early-exit conditions and, when mid->multiRsp is already\nset, abort the pending transaction inline: set multiEnd, call\ndequeue_mid() with malformed=true, and return true so handle_mid() exits\nwithout touching mid->resp_buf or the server buffer pointers."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - cifs_check_trans2() runs in cifs_demultiplex_thread on SMB1 TRANS2 responses received over TCP/445; a malicious or compromised SMB1 server (or MITM on an unsigned session) delivers the crafted primary and malformed secondary PDUs entirely over the network.\nAC:L - The attacker fully controls both fragments: a valid primary with TotalDataCount greater than DataCount sets mid->multiRsp, then a secondary with WordCount != 10, inconsistent counts, or a malformed SMB header makes cifs_check_trans2() return false. The resulting UAF is deterministic with no race outside the attacker's control.\nPR:N - The attacker is the remote SMB peer and needs no account or privileges on the victim; cifs_check_trans2() runs in the demux thread on server-supplied frames, and session credentials belong to the client mount, not the attacking server.\nUI:N - Once an SMB1 CIFS mount exists (fstab, autofs, cifsroot, embedded/industrial NAS; CONFIG_CIFS_ALLOW_INSECURE_LEGACY defaults on), reconnect and ordinary lookup/readdir/getattr plus cifs_qfs_tcon QUERY_FS_INFO issue TRANS2 automatically, so the server can trigger the UAF with no further user action.\nS:U - The use-after-free corrupts the client kernel's own CIFS receive-buffer mempool (cifs_req_poolp/cifs_sm_req_poolp) within the same host security authority; this is not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - handle_mid() overwrites mid->resp_buf without detaching server->bigbuf/smallbuf, so after the user thread frees the buffer the demux thread reuses the dangling mempool object for the next packet; that use-after-free enables heap reuse and arbitrary kernel memory disclosure.\nI:H - The same dangling server receive buffer is written by cifsd and later freed by the user thread, yielding a kernel heap use-after-free. Attacker-controlled subsequent SMB payloads and heap grooming can turn this into an arbitrary write or control-flow hijack.\nA:H - Reusing a freed CIFS small/large response buffer can fault on poisoned or unmapped slab objects and oops or panic the demux thread, and a malicious server can retrigger the primary-then-malformed-secondary sequence on every multi-part TRANS2."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb1transport.c"],"versions":[{"version":"316cf94a910f6f93d43cc574359d163ccae098a3","lessThan":"9eed72e9534b10a6d9f8f5146feff3db53aebdba","status":"affected","versionType":"git"},{"version":"316cf94a910f6f93d43cc574359d163ccae098a3","lessThan":"5e6533a683f6a851158d9f33fb4ea8f4f25d7f84","status":"affected","versionType":"git"},{"version":"316cf94a910f6f93d43cc574359d163ccae098a3","lessThan":"730d0bb19507b9e19c2fe5343109ac618e2fbce5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb1transport.c"],"versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9eed72e9534b10a6d9f8f5146feff3db53aebdba"},{"url":"https://git.kernel.org/stable/c/5e6533a683f6a851158d9f33fb4ea8f4f25d7f84"},{"url":"https://git.kernel.org/stable/c/730d0bb19507b9e19c2fe5343109ac618e2fbce5"}],"title":"smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2","x_generator":{"engine":"bippy-1.2.0"}}}}