CVE-2026-97563
In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()
The SMB1 synchronous read helper CIFSSMBRead() validates the server's DataLength against CIFSMaxBufSize and the caller's count, but never validates DataOffset. The copy source is formed as
and memcpy()'d for DataLength bytes with no check that the [DataOffset, DataOffset + DataLength) range lies within the response actually received from the server.
A malicious or compromised SMB1 server can return a response carrying an in-range DataLength and a large DataOffset, driving the source pointer past the end of the response buffer.
Leer descripción completaMostrar menos
The memcpy() then copies adjacent kernel heap into the caller's read buffer (information disclosure), or reads unmapped memory and oopses (denial of service). SMB1 is not negotiated by default; reaching this code requires an explicit vers=1.0 mount.
Both DataOffset and the received response length recorded in rsp_iov.iov_len are relative to the start of the SMB header, so reject the response unless DataOffset + DataLength fits within that length, using overflow-safe arithmetic, before forming the source pointer. The response length has been validated by the previous patch, so the DataOffset and DataLength fields can be read safely here.
While here, make data_length unsigned. It holds a length derived from unsigned on-the-wire fields and is only ever compared against unsigned quantities; print it with %u accordingly, and add __func__ to the cifs_dbg() calls in this function.
Detalles técnicos trazas, registros y código del informe original
&pSMBr->hdr.Protocol + le16_to_cpu(pSMBr->DataOffset)
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97563",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "667feba13e78d16393aacb15869f70970f422227",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "5be5bdda5863eacc964b609ba927764f253431b3",
"versionType": "git"
}
],
"programFiles": [
"fs/smb/client/cifssmb.c",
"fs/smb/client/trace.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/client/cifssmb.c",
"fs/smb/client/trace.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:06.883",
"references": [
{
"url": "https://git.kernel.org/stable/c/5be5bdda5863eacc964b609ba927764f253431b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/667feba13e78d16393aacb15869f70970f422227",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject out-of-bounds DataOffset in CIFSSMBRead()\n\nThe SMB1 synchronous read helper CIFSSMBRead() validates the server's\nDataLength against CIFSMaxBufSize and the caller's count, but never\nvalidates DataOffset. The copy source is formed as\n\n\t&pSMBr->hdr.Protocol + le16_to_cpu(pSMBr->DataOffset)\n\nand memcpy()'d for DataLength bytes with no check that the\n[DataOffset, DataOffset + DataLength) range lies within the response\nactually received from the server.\n\nA malicious or compromised SMB1 server can return a response carrying\nan in-range DataLength and a large DataOffset, driving the source\npointer past the end of the response buffer. The memcpy() then copies\nadjacent kernel heap into the caller's read buffer (information\ndisclosure), or reads unmapped memory and oopses (denial of service).\nSMB1 is not negotiated by default; reaching this code requires an\nexplicit vers=1.0 mount.\n\nBoth DataOffset and the received response length recorded in\nrsp_iov.iov_len are relative to the start of the SMB header, so reject\nthe response unless DataOffset + DataLength fits within that length,\nusing overflow-safe arithmetic, before forming the source pointer.\nThe response length has been validated by the previous patch, so the\nDataOffset and DataLength fields can be read safely here.\n\nWhile here, make data_length unsigned. It holds a length derived from\nunsigned on-the-wire fields and is only ever compared against unsigned\nquantities; print it with %u accordingly, and add __func__ to the\ncifs_dbg() calls in this function."
}
],
"lastModified": "2026-09-25T11:17:06.883",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}