KernelScan.io

CRITICAL Introduced in 2.6.12

smb DataOffset OOB

CVE-2026-97563

CVSS 9.1 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

01

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() The SMB1 synchronous read helper CIFSSMBRead() validates the server's DataLength against CIFSMaxBufSize and the caller's count, but never validates DataOffset. The copy source is formed as &pSMBr->hdr.Protocol + le16_to_cpu(pSMBr->DataOffset) and memcpy()'d for DataLength bytes with no check that the [DataOffset, DataOffset + DataLength) range lies within the response actually received from the server. A malicious or compromised SMB1 server can return a response carrying an in-range DataLength and a large DataOffset, driving the source pointer past the end of the response buffer. The memcpy() then copies adjacent kernel heap into the caller's read buffer (information disclosure), or reads unmapped memory and oopses (denial of service). SMB1 is not negotiated by default; reaching this code requires an explicit vers=1.0 mount. Both DataOffset and the received response length recorded in rsp_iov.iov_len are relative to the start of the SMB header, so reject the response unless DataOffset + DataLength fits within that length, using overflow-safe arithmetic, before forming the source pointer. The response length has been validated by the previous patch, so the DataOffset and DataLength fields can be read safely here. While here, make data_length unsigned. It holds a length derived from unsigned on-the-wire fields and is only ever compared against unsigned quantities; print it with %u accordingly, and add __func__ to the cifs_dbg() calls in this function.

02

Engine v0.6.0

Risk summary

Devices that mount SMB1 shares (vers=1.0) are at risk from malicious or compromised SMB servers. A crafted server response can leak kernel heap memory to userspace or crash the kernel. The attack requires no privileges on the client beyond the initial mount configuration.

Affectedfs/smb/client/cifssmb.c (smb client)

Vulnerability analysis

The SMB1 client read handler copies file data from a server response using an offset field supplied by that server, but never verifies the offset stays within the received message. A malicious or compromised SMB server can send a response with a valid data length but an oversized offset, driving the copy past the end of the response buffer and reading adjacent kernel heap memory—leaking it into the caller's buffer or crashing the kernel on unmapped addresses. The fix rejects any response whose data offset plus data length exceeds the actual received message size, using overflow-safe arithmetic, before forming the source pointer. This code path is only reachable when a client explicitly mounts an SMB1 share (vers=1.0, not the default), so the attacker must be a server the client has connected to, or a man-in-the-middle on that connection.

03

BranchIntroducedFixed inPatch commit
7.22.6.127.2.7667feba13e78
mainline2.6.127.3-rc35be5bdda5863