« Volver al listado

CVE-2026-72310

Estado: RecibidaAlta (8.1)—

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix overflow in passthrough ioctl bounds check

smb2_ioctl_query_info() validates the PASSTHRU_FSCTL response payload before copying it to userspace.

The payload offset and length both come from 32-bit fields. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, so the addition can wrap in 32-bit arithmetic before the result is compared against the response buffer length.

A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check. The later copy_to_user() then reads from io_rsp + OutputOffset, outside the response buffer.

Leer descripción completaMostrar menos

Use size_add() for the offset plus length check so overflow is treated as out of bounds.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad en kernel Linux que requiere PR:L (privilegios locales) para explotar un servidor SMB remoto. La lectura de memoria fuera de límites (T1005) es el impacto primario; escalada potencial (T1068) si se alcanza acceso root remoto.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72310",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "175357ee0c596cb82054650dfa32fda51ad35aaa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "dbd126539c098dba3159ce7d34b10b2daddcbd0f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "63feb687e89a3a52a31e6e01764117cc500f1974",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "160045fc943f6c46b227644261252c8a22b8a87a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "b30771b69eafae750afb7385fbcc3d77ed3f3670",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "1627e7d5c9b09721a141d07cedb178882f1ded67",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b1116bbe898aefdf584838448c6869f69851e0f",
              "lessThan": "a4f27ad055392fa164f5649e89a3637b033c5fcc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2005c32ec99ee2490e8131b3953f3f212009ffea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.4.69",
              "lessThan": "5.5",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:03.777",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/160045fc943f6c46b227644261252c8a22b8a87a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1627e7d5c9b09721a141d07cedb178882f1ded67",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/175357ee0c596cb82054650dfa32fda51ad35aaa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/63feb687e89a3a52a31e6e01764117cc500f1974",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a4f27ad055392fa164f5649e89a3637b033c5fcc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b30771b69eafae750afb7385fbcc3d77ed3f3670",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dbd126539c098dba3159ce7d34b10b2daddcbd0f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix overflow in passthrough ioctl bounds check\n\nsmb2_ioctl_query_info() validates the PASSTHRU_FSCTL response payload\nbefore copying it to userspace.\n\nThe payload offset and length both come from 32-bit fields. The bounds\ncheck currently adds OutputOffset and qi.input_buffer_length directly, so\nthe addition can wrap in 32-bit arithmetic before the result is compared\nagainst the response buffer length.\n\nA malicious server can use a large OutputOffset and a small OutputCount\nto make the wrapped sum pass the bounds check. The later copy_to_user()\nthen reads from io_rsp + OutputOffset, outside the response buffer.\n\nUse size_add() for the offset plus length check so overflow is treated as\nout of bounds."
    }
  ],
  "lastModified": "2026-08-17T06:18:34.077",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}