« Volver al listado

CVE-2026-89630

Estado: RecibidaCrítica (9.1)—

In the Linux kernel, the following vulnerability has been resolved:

smb: client: restore the data_offset bound in is_valid_oplock_break()

Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr") changed the quantity this bound is measured against. It used to be srv->total_read minus the 4-byte RFC1002 preamble that total_read then included, so it was the SMB message length. The same commit stopped counting the preamble, and the mechanical substitution to srv->total_read - srv->pdu_size left an expression that is identically zero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly pdu_length - MID_HEADER_SIZE() more, adding both to total_read.

Leer descripción completaMostrar menos

len is therefore 0, the subtraction below it wraps, and no __u32 DataOffset can exceed the result, so the check from commit 097f5863b1a0 ("cifs: read overflow in is_valid_oplock_break()") no longer rejects anything. Use total_read, which is now the message length on its own.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de lectura en buffer del cliente SMB (CIFS) en kernel Linux sin autenticación requerida (PR:N, UI:N). Vector CVSS muestra acceso remoto (AV:N) con alto impacto en confidencialidad (C:H) e impacto en disponibilidad (A:H); permite explotación remota (T1190) con potencial lectura de dato

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89630",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "83bfbd0bb9025f98fa62b44f93bd67466773d1db",
              "lessThan": "5b16a1967a01ad4496a7206a87c3eb16f1df2b05",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "83bfbd0bb9025f98fa62b44f93bd67466773d1db",
              "lessThan": "ba22f575de9deeae4ae0859ca4315a7698226237",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb1misc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb1misc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:48.517",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5b16a1967a01ad4496a7206a87c3eb16f1df2b05",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba22f575de9deeae4ae0859ca4315a7698226237",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: restore the data_offset bound in is_valid_oplock_break()\n\nCommit 83bfbd0bb902 (\"cifs: Remove the RFC1002 header from smb_hdr\")\nchanged the quantity this bound is measured against.  It used to be\nsrv->total_read minus the 4-byte RFC1002 preamble that total_read then\nincluded, so it was the SMB message length.  The same commit stopped\ncounting the preamble, and the mechanical substitution to\nsrv->total_read - srv->pdu_size left an expression that is identically\nzero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly\npdu_length - MID_HEADER_SIZE() more, adding both to total_read.\n\nlen is therefore 0, the subtraction below it wraps, and no __u32\nDataOffset can exceed the result, so the check from commit 097f5863b1a0\n(\"cifs: read overflow in is_valid_oplock_break()\") no longer rejects\nanything.  Use total_read, which is now the message length on its own."
    }
  ],
  "lastModified": "2026-09-13T07:17:28.067",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}