{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93801","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.789Z","datePublished":"2026-09-24T16:02:35.496Z","dateUpdated":"2026-09-25T12:43:08.420Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T12:43:08.420Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: zero-initialize stack-allocated cifs_open_info_data\n\nStack-allocated cifs_open_info_data may contain random data.\nThis can make some fields have wrong value if they are not set later."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - smb_set_file_info, cifs_query_mf_symlink, and __cifs_sfu_make_node allocate cifs_open_info_data on the stack and pass it to open/query_path_info. Those run only from local VFS setattr (cifs_setattr_nounix), O_TMPFILE (set_tmpfile_attr), sfu mknod/symlink, and MF-symlink lookup (check_mf_symlink), not from ksmbd or demux-thread PDU parsing.\nAC:H - smb_set_file_info calls cifs_query_path_info, which walks uninitialized wsl.eas, only when the SMB1 session lacks CAP_NT_SMBS, and that walk runs only after the query sets reparse_point from ATTR_REPARSE_POINT. A local attacker cannot strip CAP_NT_SMBS or force that DOS attribute on a typical NT/SMB2/SMB3 server.\nPR:L - cifs_setattr_nounix → cifs_set_file_info needs only inode ownership or directory write (utimensat, chmod clearing ATTR_READONLY, O_TMPFILE via set_tmpfile_attr). CIFS is not FS_USERNS_MOUNT, but using an already-mounted share does not require init-namespace CAP_SYS_ADMIN.\nUI:N - The attacker issues setattr, mknod/symlink, or lookup themselves on a share that is already mounted (fstab/autofs/CIFS home). No separate victim mount or open is required at exploit time.\nS:U - The stack out-of-bounds walk/write in cifs_query_path_info stays inside the client kernel CIFS code and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - With ATTR_REPARSE_POINT set, cifs_query_path_info walks data->wsl.eas using leftover next_entry_offset with no bound against SMB2_WSL_MAX_QUERY_EA_RESP_SIZE, an unbounded out-of-bounds read of kernel stack and adjacent memory.\nI:H - After that walk, CIFSSMBQAllEAs writes $LXMOD/$LXDEV through the wild ea pointer and the code stores next_entry_offset/ea_name_length/ea_value_length at that location, a stack out-of-bounds write.\nA:H - The while (next) loop over uninitialized next_entry_offset can spin without bound or dereference unmapped memory and oops, hanging or crashing the setattr path."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/link.c","fs/smb/client/smb1ops.c","fs/smb/client/smb2ops.c"],"versions":[{"version":"fc2f2011d3d84b56f536b4a25a4bb2fa1b13d520","lessThan":"74ff47e6c4213fcfeba2de448d9cbda200507d22","status":"affected","versionType":"git"},{"version":"057ac50638bcece64b3b436d3a61b70ed6c01a34","lessThan":"22532dd88694ed20bdd47523ffa709f166ce776b","status":"affected","versionType":"git"},{"version":"057ac50638bcece64b3b436d3a61b70ed6c01a34","lessThan":"8fce4cf4369c766a3293a05419500cbfde72e60d","status":"affected","versionType":"git"},{"version":"436cfdbc57d98808fce427d9a8d97691374989b3","status":"affected","versionType":"git"},{"version":"83d3bc866530a36a465b47cce4d2a9def2411960","status":"affected","versionType":"git"},{"version":"6.12.54","lessThan":"6.12.111","status":"affected","versionType":"semver"},{"version":"6.6.113","lessThan":"6.7","status":"affected","versionType":"semver"},{"version":"6.17.4","lessThan":"6.18","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/link.c","fs/smb/client/smb1ops.c","fs/smb/client/smb2ops.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.54","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.113"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17.4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/74ff47e6c4213fcfeba2de448d9cbda200507d22"},{"url":"https://git.kernel.org/stable/c/22532dd88694ed20bdd47523ffa709f166ce776b"},{"url":"https://git.kernel.org/stable/c/8fce4cf4369c766a3293a05419500cbfde72e60d"}],"title":"smb/client: zero-initialize stack-allocated cifs_open_info_data","x_generator":{"engine":"bippy-1.2.0"}}}}