← All Advisories

CVE-2026-97563

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97563

Key Details

CVECVE-2026-97563
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()

The SMB1 synchronous read helper CIFSSMBRead() validates the server's

DataLength against CIFSMaxBufSize and the caller's count, but never

validates DataOffset. The copy source is formed as

&pSMBr->hdr.Protocol + le16_to_cpu(pSMBr->DataOffset)

and memcpy()'d for DataLength bytes with no check that the

[DataOffset, DataOffset + DataLength) range lies within the response

actually received from the server.

A malicious or compromised SMB1 server can return a response carrying

an in-range DataLength and a large DataOffset, driving the source

pointer past the end of the response buffer. The memcpy() then copies

adjacent kernel heap into the caller's read buffer (information

disclosure), or reads unmapped memory and oopses (denial of service).

SMB1 is not negotiated by default; reaching this code requires an

explicit vers=1.0 mount.

Both DataOffset and the received response length recorded in

rsp_iov.iov_len are relative to the start of the SMB header, so reject

the response unless DataOffset + DataLength fits within that length,

using overflow-safe arithmetic, before forming the source pointer.

The response length has been validated by the previous patch, so the

DataOffset and DataLength fields can be read safely here.

While here, make data_length unsigned. It holds a length derived from

unsigned on-the-wire fields and is only ever compared against unsigned

quantities; print it with %u accordingly, and add __func__ to the

cifs_dbg() calls in this function. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97563
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97563