CVE-2026-97565 PUBLISHED

smb: client: reject short READ responses in CIFSSMBRead()

Assigner: Linux
Reserved: 24.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject short READ responses in CIFSSMBRead()

CIFSSMBRead() reads DataLengthHigh, DataLength and DataOffset out of the READ_RSP returned by the server without first checking that a whole READ_RSP was actually received. The length of the response is recorded in rsp_iov.iov_len, but nothing constrains it to be at least read_rsp_size before those fields are dereferenced.

A malicious or compromised SMB1 server can return a response shorter than the READ_RSP header, so that parsing the header itself reads past the end of the receive buffer. SMB1 is not negotiated by default; reaching this code requires an explicit vers=1.0 mount.

Reject the response unless it is at least read_rsp_size bytes long.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 0f1f77b821506a4dacab6ce7d29cf9e0c26f14cd (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to aaa221c1b1d288845b55e9c366e5ef608dfff49d (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to e6142a8bfc230c7263eb8b0475249c958ce49367 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.12 is affected
  • unaffected from 0 to 2.6.12 (excl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References