CVE-2026-89630
Received Received - Intake

SMB Client Data Offset Validation Flaw in Linux Kernel

Vulnerability report for CVE-2026-89630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: restore the data_offset bound in is_valid_oplock_break() Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr") changed the quantity this bound is measured against. It used to be srv->total_read minus the 4-byte RFC1002 preamble that total_read then included, so it was the SMB message length. The same commit stopped counting the preamble, and the mechanical substitution to srv->total_read - srv->pdu_size left an expression that is identically zero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly pdu_length - MID_HEADER_SIZE() more, adding both to total_read. len is therefore 0, the subtraction below it wraps, and no __u32 DataOffset can exceed the result, so the check from commit 097f5863b1a0 ("cifs: read overflow in is_valid_oplock_break()") no longer rejects anything. Use total_read, which is now the message length on its own.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the SMB client component. A recent code change incorrectly modified how data offsets are validated during oplock breaks. The fix introduced a calculation that always results in zero, disabling a critical bounds check. This allows malformed SMB messages to bypass security validation, potentially leading to memory corruption or other undefined behavior.

Detection Guidance

This vulnerability is specific to the Linux kernel's CIFS/SMB client implementation. Detection requires checking kernel versions and CIFS module behavior. Use 'uname -a' to verify kernel version and 'lsmod | grep cifs' to confirm CIFS module is loaded. Monitor kernel logs with 'dmesg | grep cifs' for related errors.

Impact Analysis

If exploited, this flaw could allow an attacker on the network to send specially crafted SMB messages to a vulnerable system. This might cause crashes, data corruption, or enable further attacks like privilege escalation. Systems using the Linux kernel with SMB client functionality are at risk.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for CVE-2026-89630. Monitor vendor advisories for kernel updates and apply them promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89630. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart