KernelScan.io

HIGH Introduced in 6.1

smb/client SymlinkData Loop

CVE-2026-52967

CVSS 8.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

KernelScan AI7.6HIGH

01

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite loop and oob read in symlink_data() On 32-bit architectures, the infinite loop is as follows: len = p->ErrorDataLength == 0xfffffff8 u8 *next = p->ErrorContextData + len next == p On 32-bit architectures, the out-of-bounds read is as follows: len = p->ErrorDataLength == 0xfffffff0 u8 *next = p->ErrorContextData + len next == (u8 *)p - 8

02

Engine v0.3.0

Risk summary

A malicious or compromised SMB server can send a crafted STATUS_STOPPED_ON_SYMLINK error response with a large ErrorDataLength value that causes the Linux SMB client to enter an infinite loop or perform an unbounded out-of-bounds read on 32-bit architectures when parsing symlink data. This results in a kernel hang or panic (denial of service) and potential low-level information disclosure. Any system mounting SMB/CIFS shares from an untrusted or MITM'd server is at risk.

Affectedfs/smb/client/smb2file.c (SMB2 client symlink handling)

Vulnerability analysis

The vulnerability exists in the symlink_data() function in fs/smb/client/smb2file.c. When parsing SMB2 error context responses for symlinks, the code computes 'len = ALIGN(le32_to_cpu(p->ErrorDataLength), 8)' and then advances the pointer with 'p = (struct smb2_error_context_rsp *)(p->ErrorContextData + len)'. On 32-bit architectures, if the server supplies a malicious ErrorDataLength (e.g., 0xfffffff8), the aligned length wraps around such that p->ErrorContextData + len == p, creating an infinite loop. If ErrorDataLength is 0xfffffff0, the computed next pointer points before p, causing an out-of-bounds read; with arbitrary large values, the read is unbounded and will eventually hit unmapped pages, causing a kernel panic. The fix adds a bounds check: 'if (len > end - ((u8 *)p + sizeof(*p))) return ERR_PTR(-EINVAL)' before advancing the pointer, ensuring the computed length does not exceed the remaining buffer. The attack requires the client to have an active SMB session with a malicious server (or a MITM'd server), which then returns a crafted response during symlink resolution. Once the share is mounted, no special local privileges are required to trigger the parsing path.

03

BranchIntroducedFixed inPatch commit
6.06.0.166.11cfa2d59f669
6.126.16.12.9197a05b0ae9ea
6.186.16.18.331b9331b16b0e
7.06.17.0.107d9a7f1f96cd
mainline6.17.1—
6.16.16.1.175b41598bf54b3
6.66.16.6.141cd4b9b662f0f