« Volver al listado

CVE-2026-97560

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix one-byte OOB read in smb2_parse_native_symlink()

When parsing a share-root relative native symlink, memcpy copies smb_target+1 (skipping the leading separator) but uses strlen(smb_target)+1 as the length, reading one byte past the allocated buffer.

This fixes the following KASAN splat when accessing an SMB symlink with a target of '\a\b':

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
  Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
  CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
  7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
  1996)
  Call Trace:
   <TASK>
   dump_stack_lvl+0x7b/0xa0
   print_report+0xd0/0x630
   kasan_report+0xe5/0x120
   kasan_check_range+0x105/0x1b0
   __asan_memcpy+0x23/0x60
   smb2_parse_native_symlink+0x4f5/0xca0
   parse_reparse_point+0x68a/0x1530
   reparse_info_to_fattr+0x752/0xa20
   cifs_get_fattr+0x873/0x15b0
   cifs_get_inode_info+0xc0/0x310
   cifs_lookup+0x308/0xa70
   __lookup_slow+0x122/0x2b0
   lookup_slow+0x50/0x70
   path_lookupat+0x525/0xaf0
   filename_lookup+0x1f2/0x550
   vfs_statx+0xd1/0x1a0
   vfs_fstatat+0x65/0xc0
   __do_sys_newfstatat+0x9a/0x120
   do_syscall_64+0xdd/0x4a0
   entry_SYSCALL_64_after_hwframe+0x77/0x7f

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97560",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "430afd3edabf942a908570e5a41414bb455f15f8",
              "lessThan": "ff411fcbfc55eec1d66ea82483d254319dc8e973",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fc5a409552be479715b147748f2f61b41b512976",
              "lessThan": "22a9d0a9ba0c89be57558c1aa80dc60a571dd89c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "723f4ef90452aa629f3d923e92e0449d69362b1d",
              "lessThan": "d1f173d28e964ba2c3c4ebe7491d594dc8c77a40",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "723f4ef90452aa629f3d923e92e0449d69362b1d",
              "lessThan": "2a302fdbaf7dd00d285303c94af8f48321c22993",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "723f4ef90452aa629f3d923e92e0449d69362b1d",
              "lessThan": "cb26524ef4ac28fcfa554c0656e8dc412c38a8ff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9280c017ea13ff8678ef4f1ea78a4b683292e8b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.64",
              "lessThan": "6.6.158",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.2",
              "lessThan": "6.12.111",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.11.11",
              "lessThan": "6.12",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/client/reparse.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/reparse.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:06.537",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/22a9d0a9ba0c89be57558c1aa80dc60a571dd89c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2a302fdbaf7dd00d285303c94af8f48321c22993",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb26524ef4ac28fcfa554c0656e8dc412c38a8ff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d1f173d28e964ba2c3c4ebe7491d594dc8c77a40",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff411fcbfc55eec1d66ea82483d254319dc8e973",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix one-byte OOB read in smb2_parse_native_symlink()\n\nWhen parsing a share-root relative native symlink, memcpy copies\nsmb_target+1 (skipping the leading separator) but uses\nstrlen(smb_target)+1 as the length, reading one byte past the\nallocated buffer.\n\nThis fixes the following KASAN splat when accessing an SMB symlink\nwith a target of '\\a\\b':\n\n  BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0\n  Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1\n  CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N\n  7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)\n  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,\n  1996)\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x7b/0xa0\n   print_report+0xd0/0x630\n   kasan_report+0xe5/0x120\n   kasan_check_range+0x105/0x1b0\n   __asan_memcpy+0x23/0x60\n   smb2_parse_native_symlink+0x4f5/0xca0\n   parse_reparse_point+0x68a/0x1530\n   reparse_info_to_fattr+0x752/0xa20\n   cifs_get_fattr+0x873/0x15b0\n   cifs_get_inode_info+0xc0/0x310\n   cifs_lookup+0x308/0xa70\n   __lookup_slow+0x122/0x2b0\n   lookup_slow+0x50/0x70\n   path_lookupat+0x525/0xaf0\n   filename_lookup+0x1f2/0x550\n   vfs_statx+0xd1/0x1a0\n   vfs_fstatat+0x65/0xc0\n   __do_sys_newfstatat+0x9a/0x120\n   do_syscall_64+0xdd/0x4a0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f"
    }
  ],
  "lastModified": "2026-10-03T11:18:03.730",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}