KernelScan.io

CRITICAL Introduced in 2.6.12

smb ReadRsp OOB

CVE-2026-97565

CVSS 9.1 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

01

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject short READ responses in CIFSSMBRead() CIFSSMBRead() reads DataLengthHigh, DataLength and DataOffset out of the READ_RSP returned by the server without first checking that a whole READ_RSP was actually received. The length of the response is recorded in rsp_iov.iov_len, but nothing constrains it to be at least read_rsp_size before those fields are dereferenced. A malicious or compromised SMB1 server can return a response shorter than the READ_RSP header, so that parsing the header itself reads past the end of the receive buffer. SMB1 is not negotiated by default; reaching this code requires an explicit vers=1.0 mount. Reject the response unless it is at least read_rsp_size bytes long.

02

Engine v0.6.0

Risk summary

This vulnerability affects Linux systems that mount SMB1 shares (vers=1.0) and communicate with a malicious or compromised SMB server. The server can trigger an out-of-bounds read in the client kernel by returning a truncated read response, potentially leaking stale buffer contents or causing a kernel fault. SMB1 is not negotiated by default, so only systems with explicit SMB1 mounts are affected.

Affectedfs/smb/client/cifssmb.c (smb client)

Vulnerability analysis

The SMB1 client reads fixed fields from a server's read response without first verifying that the response is long enough to contain the full header, so a response shorter than the expected structure causes the client to read past the end of the receive buffer. The fix rejects any response whose length is below the expected header size, returning an error instead of parsing the truncated header. This code path is only reached when a client has explicitly mounted an SMB1 share (vers=1.0), which requires root privileges on the client; the attacker is a malicious or compromised SMB server responding to the client's read requests, or a man-in-the-middle positioned between them.

03

BranchIntroducedFixed inPatch commit
6.182.6.126.18.530f1f77b82150
7.22.6.127.2.7aaa221c1b1d2
mainline2.6.127.3-rc3e6142a8bfc23