CVE-2026-89637
Received Received - Intake

Use-After-Free and Buffer Leak in Linux Kernel SMB Client

Vulnerability report for CVE-2026-89637, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid->resp_buf with the new buffer (leaking the primary buffer) and, because mid->multiRsp is set, skips the server->smallbuf/bigbuf NULL-out. When the user thread frees mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid->multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid->resp_buf or the server buffer pointers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a use-after-free (UAF) and buffer leak in the cifs_check_trans2() function when handling malformed secondary SMB TRANSACT2 responses. It occurs when a valid primary response is received, followed by an invalid secondary response, causing the function to incorrectly overwrite buffers and leave dangling pointers. This leads to memory corruption when the buffers are reused by the demux thread.

Detection Guidance

This vulnerability is specific to the Linux kernel's CIFS/SMB client implementation and requires kernel-level detection. There are no direct network or system commands to detect this issue as it involves internal kernel memory handling. Monitoring kernel logs for SMB-related errors or crashes may indicate exploitation attempts. Ensure your Linux kernel is updated to a patched version.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code, escalate privileges, or cause system crashes by exploiting the UAF condition. It primarily affects systems using the Linux kernel with SMB client functionality, potentially leading to unauthorized access or denial of service.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a low-level Linux kernel issue involving memory corruption in the SMB client component. Compliance impacts would only occur if this vulnerability were exploited to gain unauthorized access to sensitive data or disrupt systems handling protected information.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve the UAF and buffer leak in cifs_check_trans2(). Monitor network traffic for malformed SMB TRANSACT2 responses as a potential indicator of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89637. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart