CRITICAL Introduced in 4.11
smb PathConsumed OOB
CVE-2026-68343
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
KernelScan AI9.1CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response also contains a PathConsumed value that is later used for DFS path parsing. If a malformed response provides a PathConsumed value larger than the search name, later DFS parsing can advance beyond the end of the path. Validate PathConsumed against the search name length before storing it in the parsed referral.
02KernelScan AI Analysis
Risk summary
A malicious or man-in-the-middle SMB server can send a DFS referral response with an oversized PathConsumed value, causing the Linux SMB client kernel code to read beyond the end of an allocated buffer. This can leak kernel memory or crash the system. Any system that mounts SMB/CIFS shares with DFS is at risk when connecting to an untrusted server.
Vulnerability analysis
When the SMB client processes a DFS referral response from a server, a PathConsumed field in the response is used to advance through the search path during DFS path parsing without being checked against the actual length of the search name. A malformed response with a PathConsumed value larger than the search name causes later parsing to read past the end of the allocated path buffer, resulting in an unbounded out-of-bounds read. The fix validates PathConsumed against the search name length (in both Unicode and non-Unicode modes) before storing it, rejecting any response where the value exceeds the valid range. This is reachable by any SMB client that connects to a malicious or compromised server, or by a network attacker who can intercept SMB traffic; no privileges on the client are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 4.11 | 6.12.101 | 285bd4a5f3f1 |
| 6.18 | 4.11 | 6.18.42 | 2fdd6d196c65 |
| 6.6 | 4.11 | 6.6.148 | 5b439f39f33e |
| 7.1 | 4.11 | 7.1.6 | 9f88a99ed511 |
| 6.1 | 4.11 | 6.1.183 | bfebe5110fd1 |
| mainline | 4.11 | 7.2 | f6f5ee2aa33b |