HIGH Introduced in 6.1
smb/client SymlinkData Loop
CVE-2026-52967
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
KernelScan AI7.6HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite loop and oob read in symlink_data() On 32-bit architectures, the infinite loop is as follows: len = p->ErrorDataLength == 0xfffffff8 u8 *next = p->ErrorContextData + len next == p On 32-bit architectures, the out-of-bounds read is as follows: len = p->ErrorDataLength == 0xfffffff0 u8 *next = p->ErrorContextData + len next == (u8 *)p - 8
02KernelScan AI Analysis
Risk summary
A malicious or compromised SMB server can send a crafted STATUS_STOPPED_ON_SYMLINK error response with a large ErrorDataLength value that causes the Linux SMB client to enter an infinite loop or perform an unbounded out-of-bounds read on 32-bit architectures when parsing symlink data. This results in a kernel hang or panic (denial of service) and potential low-level information disclosure. Any system mounting SMB/CIFS shares from an untrusted or MITM'd server is at risk.
Vulnerability analysis
The vulnerability exists in the symlink_data() function in fs/smb/client/smb2file.c. When parsing SMB2 error context responses for symlinks, the code computes 'len = ALIGN(le32_to_cpu(p->ErrorDataLength), 8)' and then advances the pointer with 'p = (struct smb2_error_context_rsp *)(p->ErrorContextData + len)'. On 32-bit architectures, if the server supplies a malicious ErrorDataLength (e.g., 0xfffffff8), the aligned length wraps around such that p->ErrorContextData + len == p, creating an infinite loop. If ErrorDataLength is 0xfffffff0, the computed next pointer points before p, causing an out-of-bounds read; with arbitrary large values, the read is unbounded and will eventually hit unmapped pages, causing a kernel panic. The fix adds a bounds check: 'if (len > end - ((u8 *)p + sizeof(*p))) return ERR_PTR(-EINVAL)' before advancing the pointer, ensuring the computed length does not exceed the remaining buffer. The attack requires the client to have an active SMB session with a malicious server (or a MITM'd server), which then returns a crafted response during symlink resolution. Once the share is mounted, no special local privileges are required to trigger the parsing path.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.0 | 6.0.16 | 6.1 | 1cfa2d59f669 |
| 6.12 | 6.1 | 6.12.91 | 97a05b0ae9ea |
| 6.18 | 6.1 | 6.18.33 | 1b9331b16b0e |
| 7.0 | 6.1 | 7.0.10 | 7d9a7f1f96cd |
| mainline | 6.1 | 7.1 | — |
| 6.1 | 6.1 | 6.1.175 | b41598bf54b3 |
| 6.6 | 6.1 | 6.6.141 | cd4b9b662f0f |