CVE-2026-89631
Received Received - Intake

Buffer Overflow in Linux Kernel SMB Client

Vulnerability report for CVE-2026-89631, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject a tree connect response whose byte count is too small CIFSTCon() bounds its strnlen() over the byte area with the server's ByteCount minus two, which for ByteCount 0 or 1 goes negative as an int and converts to a huge size_t. The later subtraction wraps the __u16 bytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of up to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the slab object, and the bytes reach userspace through tcon->nativeFileSystem in /proc/fs/cifs/DebugData. Reject a byte area too small for what the parser consumes. Two bytes is the least it can consume, and no conformant response carries fewer. The new trace point is the 129th smb_eio_trace entry, which __mode(byte) cannot represent, so the attribute goes with it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the SMB (Server Message Block) client code. When processing a tree connect response from a server, the code incorrectly handles cases where the response's byte count is too small. This leads to a negative integer value being converted to a large size_t, causing a buffer overflow in the cifs_strndup_from_utf16() function. The overflow can corrupt memory in the cifs_req_poolp object, potentially exposing kernel memory to userspace through the /proc/fs/cifs/DebugData file.

Detection Guidance

This vulnerability involves a buffer overflow in the Linux kernel's SMB client due to improper bounds checking on server responses. Detection requires monitoring for abnormal SMB traffic or kernel crashes. Check kernel logs for slab overflow errors or CIFS-related warnings. Use tools like dmesg or journalctl to inspect kernel messages for memory corruption signs. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

This vulnerability could allow an attacker to cause a denial of service by crashing the system or to potentially execute arbitrary code with kernel privileges. If exploited, it may lead to unauthorized access to sensitive data, system instability, or further compromise of the affected machine.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel SMB client issue that could lead to memory corruption or information disclosure, but no evidence suggests it impacts regulatory compliance frameworks.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve this vulnerability. Monitor vendor advisories for kernel updates and apply them promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89631. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart