« Volver al listado

CVE-2026-68431

Estado: RecibidaCrítica (9.1)—

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate minimum PDU size for transform requests

The receive path applies the minimum SMB2 PDU size check only when ProtocolId is SMB2_PROTO_NUMBER. A packet carrying SMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated dialect does not provide transform handling.

On an SMB 2.1 connection, a short transform packet therefore reaches init_smb2_rsp_hdr(), which interprets the request as a full SMB2 header and reads beyond the request allocation. The copied fields can then be returned to the unauthenticated client.

Leer descripción completaMostrar menos

Compression transforms are converted to ordinary SMB2 messages before protocol validation. After that conversion, validate ordinary SMB2 requests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption transform requests to contain both a transform header and an SMB2 header. This rejects truncated requests before work allocation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota en ksmbd sin autenticación (AV:N, PR:N, UI:N) que permite leer memoria más allá del búfer (C:H) y causar DoS (A:H) al interpretar paquetes SMB2 truncados sin validación mínima de PDU.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68431",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "df3a4518aee64f21bcafa891105b468413f27431",
              "lessThan": "22f1aa35b87e471cc31b35b74451f46630863b12",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "543c12c2644e772caa6880662c2a852cfdc5a10c",
              "lessThan": "928dda88d0e13fbca381255028f65b244343a4ea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
              "lessThan": "d8e5c5672724b8f3c4c099d2cf60239c996e5424",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
              "lessThan": "32e486b70c256d5ef4baa5a2936ade2fea50e8eb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
              "lessThan": "d9e9753dfd43bd27c956578df7804a3c90b80fdc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
              "lessThan": "b62c510f59803f82f9b4c76ead2a56833b2984c7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "368ba06881c395f1c9a7ba22203cf8d78b4addc0",
              "lessThan": "cfc0b8e5080aec87700774e8568765eaa4b7b92b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9cb7be2fcbaee9e808b729e92948d38d52e5add",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.15.145",
              "lessThan": "5.15.217",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.34",
              "lessThan": "6.1.184",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.3.8",
              "lessThan": "6.4",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/server/connection.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.153",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.105",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.46",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/server/connection.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-12T00:17:43.180",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/22f1aa35b87e471cc31b35b74451f46630863b12",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/32e486b70c256d5ef4baa5a2936ade2fea50e8eb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/928dda88d0e13fbca381255028f65b244343a4ea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b62c510f59803f82f9b4c76ead2a56833b2984c7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cfc0b8e5080aec87700774e8568765eaa4b7b92b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d8e5c5672724b8f3c4c099d2cf60239c996e5424",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d9e9753dfd43bd27c956578df7804a3c90b80fdc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate minimum PDU size for transform requests\n\nThe receive path applies the minimum SMB2 PDU size check only when\nProtocolId is SMB2_PROTO_NUMBER. A packet carrying\nSMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated\ndialect does not provide transform handling.\n\nOn an SMB 2.1 connection, a short transform packet therefore reaches\ninit_smb2_rsp_hdr(), which interprets the request as a full SMB2 header\nand reads beyond the request allocation. The copied fields can then be\nreturned to the unauthenticated client.\n\nCompression transforms are converted to ordinary SMB2 messages before\nprotocol validation. After that conversion, validate ordinary SMB2\nrequests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption\ntransform requests to contain both a transform header and an SMB2\nheader. This rejects truncated requests before work allocation."
    }
  ],
  "lastModified": "2026-08-23T13:16:36.823",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}