KernelScan.io

HIGH

ksmbd ShareConfig OOB

CVE-2026-89792

CVSS 7.1 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

KernelScan AI6.8MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config responses Validate IPC share configuration payload sizes before consuming variable-length fields. Bound veto list parsing and account for the separator byte when deriving the path length.

02

Engine v0.6.0

Risk summary

The ksmbd SMB server kernel module fails to properly validate IPC share configuration payload sizes, allowing out-of-bounds reads when processing veto lists and share paths. An attacker who can control or influence the ksmbd.mountd userspace daemon can trigger these reads, potentially leaking kernel memory or causing a kernel panic.

Affectedfs/smb/server/mgmt/share_config.c, fs/smb/server/transport_ipc.c (ksmbd)

Vulnerability analysis

The ksmbd kernel server processes IPC responses from the ksmbd.mountd userspace daemon to obtain share configuration, but the original code does not properly validate the sizes of variable-length fields within these responses. When parsing veto lists, it uses unbounded string operations that can read past the allocated buffer, and when deriving the share path length, it fails to account for a separator byte, leading to an incorrect length that can cause an out-of-bounds read. The fix adds strict validation of payload sizes before any variable-length field is consumed, replaces unbounded string operations with bounded equivalents, and correctly accounts for the separator byte when computing the path length. This vulnerability is reachable from a local process that can influence or replace the ksmbd.mountd daemon, requiring no special kernel privileges beyond the ability to run or control that userspace helper.

03

BranchIntroducedFixed inPatch commit
5.155.15.1575.16ffa507f5f774
6.16.1.856.2cd2bcee450bc
6.66.6.266.761a8d06600c8
6.12—6.12.111—
6.18—6.18.53—
7.2—7.2.6—
mainline—7.3-rc2—
6.86.8.56.9f25e93768fcc