« Volver al listado

CVE-2026-90170

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate ipc response length before dereferencing its fields

ipc_validate_msg() computes the expected message size by reading length fields out of the response buffer supplied by the userspace ksmbd daemon (payload_sz, session_key_len, ngroups, ...). Those fields are read before the buffer is verified to be large enough to contain the struct they belong to, so a short response makes the read land past the end of the allocation.

handle_response() sizes entry->response purely from the netlink attribute length (nla_len()) and only guards the leading handle read, so the daemon can install a response as small as the kmalloc-8 object seen below.

Leer descripción completaMostrar menos

When ipc_msg_send_request() then calls ipc_validate_msg() for a KSMBD_EVENT_RPC_REQUEST, the cast to struct ksmbd_rpc_command reads resp->payload_sz at offset 8 of an 8-byte allocation:

Detalles técnicos trazas, registros y código del informe original
[ 3697.841381] ==================================================================
[ 3697.844099] BUG: KASAN: slab-out-of-bounds in ipc_msg_send_request+0x763/0x800
[ 3697.846604] Read of size 4 at addr ffff888105f95910 by task kworker/4:3/20682
[ 3697.849061]
[ 3697.849801] CPU: 4 UID: 0 PID: 20682 Comm: kworker/4:3 Not tainted 7.2.0-rc3-next-20260717-virtme #117 PREEMPT(lazy)
[ 3697.850077] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
[ 3697.850303] Workqueue: ksmbd-io handle_ksmbd_work
[ 3697.850592] Call Trace:
[ 3697.850794]  <TASK>
[ 3697.850952]  __dump_stack+0x21/0x60
[ 3697.851239]  dump_stack_lvl+0xc2/0x100
[ 3697.851528]  print_address_description+0x77/0x200
[ 3697.851816]  ? ipc_msg_send_request+0x763/0x800
[ 3697.852024]  print_report+0x58/0x70
[ 3697.852316]  kasan_report+0x117/0x150
[ 3697.852585]  ? down_write+0x146/0x1f0
[ 3697.852809]  ? ipc_msg_send_request+0x763/0x800
[ 3697.853082]  ipc_msg_send_request+0x763/0x800
[ 3697.853385]  ? __pfx_ipc_msg_send_request+0x10/0x10
[ 3697.853604]  ? kasan_unpoison+0x48/0x70
[ 3697.853936]  ? __pfx___up_read+0x10/0x10
[ 3697.854221]  ksmbd_rpc_ioctl+0x380/0x520
[ 3697.854542]  ? __pfx_ksmbd_rpc_ioctl+0x10/0x10
[ 3697.854757]  ? kasan_unpoison+0x48/0x70
[ 3697.854962]  ? copy_from_kernel_nofault+0x32c/0x4e0
[ 3697.855166]  ? kasan_unpoison+0x48/0x70
[ 3697.855416]  fsctl_pipe_transceive+0x139/0x7a0
[ 3697.855705]  ? __pfx_copy_from_kernel_nofault+0x10/0x10
[ 3697.855937]  ? __pfx_fsctl_pipe_transceive+0x10/0x10
[ 3697.856388]  ? __sanitizer_cov_trace_switch+0x7b/0x140
[ 3697.856620]  smb2_ioctl+0x1141/0x3420
[ 3697.856994]  ? __pfx_smb2_ioctl+0x10/0x10
[ 3697.857182]  ? get_smb2_cmd_val+0xe3/0x1c0
[ 3697.857655]  handle_ksmbd_work+0x9ad/0x15e0
[ 3697.858034]  ? __pfx_handle_ksmbd_work+0x10/0x10
[ 3697.858251]  ? lock_release+0xf7/0x360
[ 3697.858466]  ? process_scheduled_works+0x954/0x1600
[ 3697.858698]  ? process_scheduled_works+0x954/0x1600
[ 3697.858905]  process_scheduled_works+0xc22/0x1600
[ 3697.859368]  ? __pfx_process_scheduled_works+0x10/0x10
[ 3697.859637]  ? __pfx_assign_work+0x10/0x10
[ 3697.859896]  ? lock_is_held_type+0x7b/0x110
[ 3697.860146]  worker_thread+0x975/0xee0
[ 3697.860524]  ? __pfx_do_raw_spin_lock+0x10/0x10
[ 3697.860830]  ? __kthread_parkme+0x21e/0x260
[ 3697.861105]  kthread+0x3a6/0x490
[ 3697.861423]  ? __pfx_worker_thread+0x10/0x10
[ 3697.861643]  ? __pfx_kthread+0x10/0x10
[ 3697.861878]  ret_from_fork+0x55a/0xa20
[ 3697.862194]  ? __pfx_ret_from_fork+0x10/0x10
[ 3697.862480]  ? __pfx_kthread+0x10/0x10
[ 3697.862714]  ret_from_fork_asm+0x1a/0x30
[ 3697.862965]  </TASK>
[ 3697.863039]
[ 3697.938882] Allocated by task 20761:
[ 3697.940257]  kasan_save_track+0x3e/0x80
[ 3697.941782]  __kasan_kmalloc+0x72/0x90
[ 3697.943228]  __kvmalloc_node_noprof+0x3e9/0x6a0
[ 3697.944948]  handle_generic_event+0x59b/0x750
[ 3697.946592]  genl_family_rcv_msg_doit+0x3d6/0x560
[ 3697.946977]  genl_rcv_msg+0x67c/0x900
[ 3697.947224]  netlink_rcv_skb+0x286/0x580
[ 3697.947488]  genl_rcv+0x2d/0x80
[ 3
---truncated---

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90170",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bf396208418371174869baba9434535cd3288e80",
              "lessThan": "17b7d1a2b4d5473df5dca8c9a07d65021806c23a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7dd0c858e1909769a4c91842724315ee74f1a5f1",
              "lessThan": "398cba4b646a6c08ff3d79e6b1e70e5ddae8a065",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "299db777ea0cfa5c407e41b045c24a14c034c27b",
              "lessThan": "0aa8f94bfd4d818284c8a7ce0040d40ca1ec3595",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d6a6aa81eac2c9bff66dc6e191179cb69a14426b",
              "lessThan": "c494fcf8e89e3c970e13d78ebe62bf5d8f2b1c52",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d6a6aa81eac2c9bff66dc6e191179cb69a14426b",
              "lessThan": "e9b33376bd07bca4175f7bcc2d6034ef250f8181",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99c631d0366c1eab8fb188fe66425f4581ebdde4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.141",
              "lessThan": "6.6.157",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.84",
              "lessThan": "6.12.110",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.25",
              "lessThan": "6.18.52",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.0.2",
              "lessThan": "7.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/server/transport_ipc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/server/transport_ipc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:10.467",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0aa8f94bfd4d818284c8a7ce0040d40ca1ec3595",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/17b7d1a2b4d5473df5dca8c9a07d65021806c23a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/398cba4b646a6c08ff3d79e6b1e70e5ddae8a065",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c494fcf8e89e3c970e13d78ebe62bf5d8f2b1c52",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e9b33376bd07bca4175f7bcc2d6034ef250f8181",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate ipc response length before dereferencing its fields\n\nipc_validate_msg() computes the expected message size by reading length\nfields out of the response buffer supplied by the userspace ksmbd daemon\n(payload_sz, session_key_len, ngroups, ...).  Those fields are read before\nthe buffer is verified to be large enough to contain the struct they belong\nto, so a short response makes the read land past the end of the allocation.\n\nhandle_response() sizes entry->response purely from the netlink attribute\nlength (nla_len()) and only guards the leading handle read, so the daemon\ncan install a response as small as the kmalloc-8 object seen below.  When\nipc_msg_send_request() then calls ipc_validate_msg() for a\nKSMBD_EVENT_RPC_REQUEST, the cast to struct ksmbd_rpc_command reads\nresp->payload_sz at offset 8 of an 8-byte allocation:\n\n[ 3697.841381] ==================================================================\n[ 3697.844099] BUG: KASAN: slab-out-of-bounds in ipc_msg_send_request+0x763/0x800\n[ 3697.846604] Read of size 4 at addr ffff888105f95910 by task kworker/4:3/20682\n[ 3697.849061]\n[ 3697.849801] CPU: 4 UID: 0 PID: 20682 Comm: kworker/4:3 Not tainted 7.2.0-rc3-next-20260717-virtme #117 PREEMPT(lazy)\n[ 3697.850077] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n[ 3697.850303] Workqueue: ksmbd-io handle_ksmbd_work\n[ 3697.850592] Call Trace:\n[ 3697.850794]  <TASK>\n[ 3697.850952]  __dump_stack+0x21/0x60\n[ 3697.851239]  dump_stack_lvl+0xc2/0x100\n[ 3697.851528]  print_address_description+0x77/0x200\n[ 3697.851816]  ? ipc_msg_send_request+0x763/0x800\n[ 3697.852024]  print_report+0x58/0x70\n[ 3697.852316]  kasan_report+0x117/0x150\n[ 3697.852585]  ? down_write+0x146/0x1f0\n[ 3697.852809]  ? ipc_msg_send_request+0x763/0x800\n[ 3697.853082]  ipc_msg_send_request+0x763/0x800\n[ 3697.853385]  ? __pfx_ipc_msg_send_request+0x10/0x10\n[ 3697.853604]  ? kasan_unpoison+0x48/0x70\n[ 3697.853936]  ? __pfx___up_read+0x10/0x10\n[ 3697.854221]  ksmbd_rpc_ioctl+0x380/0x520\n[ 3697.854542]  ? __pfx_ksmbd_rpc_ioctl+0x10/0x10\n[ 3697.854757]  ? kasan_unpoison+0x48/0x70\n[ 3697.854962]  ? copy_from_kernel_nofault+0x32c/0x4e0\n[ 3697.855166]  ? kasan_unpoison+0x48/0x70\n[ 3697.855416]  fsctl_pipe_transceive+0x139/0x7a0\n[ 3697.855705]  ? __pfx_copy_from_kernel_nofault+0x10/0x10\n[ 3697.855937]  ? __pfx_fsctl_pipe_transceive+0x10/0x10\n[ 3697.856388]  ? __sanitizer_cov_trace_switch+0x7b/0x140\n[ 3697.856620]  smb2_ioctl+0x1141/0x3420\n[ 3697.856994]  ? __pfx_smb2_ioctl+0x10/0x10\n[ 3697.857182]  ? get_smb2_cmd_val+0xe3/0x1c0\n[ 3697.857655]  handle_ksmbd_work+0x9ad/0x15e0\n[ 3697.858034]  ? __pfx_handle_ksmbd_work+0x10/0x10\n[ 3697.858251]  ? lock_release+0xf7/0x360\n[ 3697.858466]  ? process_scheduled_works+0x954/0x1600\n[ 3697.858698]  ? process_scheduled_works+0x954/0x1600\n[ 3697.858905]  process_scheduled_works+0xc22/0x1600\n[ 3697.859368]  ? __pfx_process_scheduled_works+0x10/0x10\n[ 3697.859637]  ? __pfx_assign_work+0x10/0x10\n[ 3697.859896]  ? lock_is_held_type+0x7b/0x110\n[ 3697.860146]  worker_thread+0x975/0xee0\n[ 3697.860524]  ? __pfx_do_raw_spin_lock+0x10/0x10\n[ 3697.860830]  ? __kthread_parkme+0x21e/0x260\n[ 3697.861105]  kthread+0x3a6/0x490\n[ 3697.861423]  ? __pfx_worker_thread+0x10/0x10\n[ 3697.861643]  ? __pfx_kthread+0x10/0x10\n[ 3697.861878]  ret_from_fork+0x55a/0xa20\n[ 3697.862194]  ? __pfx_ret_from_fork+0x10/0x10\n[ 3697.862480]  ? __pfx_kthread+0x10/0x10\n[ 3697.862714]  ret_from_fork_asm+0x1a/0x30\n[ 3697.862965]  </TASK>\n[ 3697.863039]\n[ 3697.938882] Allocated by task 20761:\n[ 3697.940257]  kasan_save_track+0x3e/0x80\n[ 3697.941782]  __kasan_kmalloc+0x72/0x90\n[ 3697.943228]  __kvmalloc_node_noprof+0x3e9/0x6a0\n[ 3697.944948]  handle_generic_event+0x59b/0x750\n[ 3697.946592]  genl_family_rcv_msg_doit+0x3d6/0x560\n[ 3697.946977]  genl_rcv_msg+0x67c/0x900\n[ 3697.947224]  netlink_rcv_skb+0x286/0x580\n[ 3697.947488]  genl_rcv+0x2d/0x80\n[ 3\n---truncated---"
    }
  ],
  "lastModified": "2026-09-17T17:17:10.467",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}