KernelScan.io

CRITICAL Introduced in 3.6

smb Trans2Response UAF

CVE-2026-89637

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid->resp_buf with the new buffer (leaking the primary buffer) and, because mid->multiRsp is set, skips the server->smallbuf/bigbuf NULL-out. When the user thread frees mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid->multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid->resp_buf or the server buffer pointers.

02

Engine v0.6.0

Risk summary

A malicious or compromised SMB server can trigger a use-after-free in the Linux CIFS client kernel by sending a malformed secondary TRANSACT2 response after a valid primary one. This can lead to arbitrary kernel memory corruption, enabling code execution, information disclosure, or denial of service on any client machine that has an active SMB mount. The attack requires no privileges on the victim client and is triggered entirely through network-received server responses.

Affectedfs/smb/client/smb1transport.c (smb client)

Vulnerability analysis

When the CIFS client receives a valid primary transaction response followed by a malformed secondary response, the error-handling path replaces the stored primary buffer without releasing the server's reference to it. Because the client already flagged this transaction as having multiple parts, the cleanup step that normally clears the server's reference is skipped. Later, when the user's thread frees the replaced buffer, the server still holds a stale pointer to that memory. The background thread that reads incoming network traffic then reuses the freed memory for the next packet, causing a use-after-free. The corrected code now aborts the transaction immediately when a malformed secondary response arrives after a valid primary one, finalizing the transaction and removing it from the pending queue without touching the buffer or server references. Any system with an active SMB mount is exposed; the attacker can be the SMB server itself or a man-in-the-middle on the connection, and needs no privileges on the victim machine.

03

BranchIntroducedFixed inPatch commit
7.23.67.2.45e6533a683f6
mainline3.67.3-rc1730d0bb19507
6.183.66.18.519eed72e9534b