CRITICAL Introduced in 3.6
smb Trans2Response UAF
CVE-2026-89637
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid->resp_buf with the new buffer (leaking the primary buffer) and, because mid->multiRsp is set, skips the server->smallbuf/bigbuf NULL-out. When the user thread frees mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid->multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid->resp_buf or the server buffer pointers.
02KernelScan AI Analysis
Risk summary
A malicious or compromised SMB server can trigger a use-after-free in the Linux CIFS client kernel by sending a malformed secondary TRANSACT2 response after a valid primary one. This can lead to arbitrary kernel memory corruption, enabling code execution, information disclosure, or denial of service on any client machine that has an active SMB mount. The attack requires no privileges on the victim client and is triggered entirely through network-received server responses.
Vulnerability analysis
When the CIFS client receives a valid primary transaction response followed by a malformed secondary response, the error-handling path replaces the stored primary buffer without releasing the server's reference to it. Because the client already flagged this transaction as having multiple parts, the cleanup step that normally clears the server's reference is skipped. Later, when the user's thread frees the replaced buffer, the server still holds a stale pointer to that memory. The background thread that reads incoming network traffic then reuses the freed memory for the next packet, causing a use-after-free. The corrected code now aborts the transaction immediately when a malformed secondary response arrives after a valid primary one, finalizing the transaction and removing it from the pending queue without touching the buffer or server references. Any system with an active SMB mount is exposed; the attacker can be the SMB server itself or a man-in-the-middle on the connection, and needs no privileges on the victim machine.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.2 | 3.6 | 7.2.4 | 5e6533a683f6 |
| mainline | 3.6 | 7.3-rc1 | 730d0bb19507 |
| 6.18 | 3.6 | 6.18.51 | 9eed72e9534b |