CVE-2026-64257 PUBLISHED

smb: client: reject overlapping data areas in SMB2 responses

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject overlapping data areas in SMB2 responses

Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception.

Track data area overlap separately and reject such responses before applying the length compatibility exceptions.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 31c6312608c60b72a1feb99a5afb680645a3e8a3 to 445ece263131780dee273d727a4d6f11934feec7 (excl.)
  • affected from 573e502d14714d2947e22e7eff40ec20a6a44a42 to 36bfa52459e45c0d5b668de2f1c91f6dc5c67775 (excl.)
  • affected from 419ec1b604d7fb60c10aec2dc062371f9fcd4940 to 4a9d2657d3e05f6ed09c148cb127b4e58702275f (excl.)
  • affected from ceb875a375dedbf51c9425c1d13a2d7a8435c08c to fdafa1e68dc75045b7b617e6e7d2854950804d83 (excl.)
  • affected from 6e9d10f62773b99bd927940fd9cbdfe7207e23ff to 57cba95f0e97c6f6e45e6731da30aff091bd7460 (excl.)
  • affected from 53b7c271f06be4dd5cfc8c6ef552a8355c891a7f to 8986c932905ea508d66da421eb2eb6e676ace1fe (excl.)
  • Version 8d0bbc78046d264bbf6a574ea6f9072258a43e35 is affected
  • Version b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0 is affected
  • affected from 5.10.261 to 5.11 (excl.)
  • affected from 5.15.212 to 5.16 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.2-rc3 is affected
  • unaffected from 0 to 7.2-rc3 (excl.)
  • unaffected from 7.2-rc4 to * (incl.)

References