CRITICAL Introduced in 7.2-rc3
ksmbd ChannelKey Overflow
CVE-2026-72044
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix stack buffer overflow in multichannel session-key copy Commit 4b706360ffb7 ("ksmbd: fix multichannel binding and enforce channel limit") moved the binding-path session key out of the session-wide sess->sess_key (CIFS_KEY_SIZE = 40) into a new per-channel buffer, and sized both that buffer and the on-stack copy used during binding with SMB2_NTLMV2_SESSKEY_SIZE (16): struct channel { char sess_key[SMB2_NTLMV2_SESSKEY_SIZE]; /* 16 */ ... }; ntlm_authenticate() / krb5_authenticate(): char channel_key[SMB2_NTLMV2_SESSKEY_SIZE] = {}; /* 16 */ char *auth_key = conn->binding ? channel_key : sess->sess_key; The two writers that fill this destination still bound the copy length against CIFS_KEY_SIZE (40), not against the 16-byte buffer: ksmbd_decode_ntlmssp_auth_blob() (NTLM key exchange): if (sess_key_len > CIFS_KEY_SIZE) /* 40 */ return -EINVAL; arc4_crypt(ctx_arc4, sess_key, (char *)authblob + sess_key_off, sess_key_len); ksmbd_krb5_authenticate(): if (resp->session_key_len > sizeof(sess->sess_key)) /* 40 */ ... memcpy(sess_key, resp->payload, resp->session_key_len); On a binding SESSION_SETUP, auth_key points at the 16-byte channel_key, so a client that supplies an NTLM EncryptedRandomSessionKey of up to 40 bytes (with NTLMSSP_NEGOTIATE_KEY_EXCH), or a Kerberos ticket whose session key is longer than 16 bytes (a normal AES256 key is 32), writes past the 16-byte stack buffer -- up to a 24-byte kernel stack overflow. KASAN reports it as a stack-out-of-bounds write in arc4_crypt() called from ksmbd_decode_ntlmssp_auth_blob(). The destinations must be able to hold the full session key the length checks already permit. Size the per-channel key buffer and the two on-stack channel_key buffers with CIFS_KEY_SIZE, matching sess->sess_key.
02KernelScan AI Analysis
Risk summary
A remote, unauthenticated attacker who can reach the ksmbd SMB server can trigger a stack buffer overflow of up to 24 bytes during multichannel session binding. This can lead to kernel memory corruption, potentially enabling code execution, information disclosure, or a system crash. Any device running ksmbd with the vulnerable kernel version and network exposure is at critical risk.
Vulnerability analysis
When an SMB client initiates a multichannel binding session, ksmbd copies the negotiated session key into a per-channel stack buffer that was sized for 16 bytes, while the length validation still permits keys up to 40 bytes. A remote client can supply a session key longer than 16 bytes — for example a standard 32-byte AES256 Kerberos key or an NTLM encrypted session key up to 40 bytes — causing the copy to write up to 24 bytes past the end of the stack buffer. The fix enlarges both the per-channel key buffer and the on-stack copy buffer to 40 bytes, matching the length checks that were already in place. The vulnerable path is reached by any unauthenticated network client that can connect to the ksmbd TCP listener and begin a multichannel SESSION_SETUP exchange; no prior authentication or local access is required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 7.2-rc3 | 7.2-rc4 | 9a7f7b55d7d0 |