← All Advisories

CVE-2026-97565

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97565

Key Details

CVECVE-2026-97565
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject short READ responses in CIFSSMBRead()

CIFSSMBRead() reads DataLengthHigh, DataLength and DataOffset out of

the READ_RSP returned by the server without first checking that a

whole READ_RSP was actually received. The length of the response is

recorded in rsp_iov.iov_len, but nothing constrains it to be at least

read_rsp_size before those fields are dereferenced.

A malicious or compromised SMB1 server can return a response shorter

than the READ_RSP header, so that parsing the header itself reads past

the end of the receive buffer. SMB1 is not negotiated by default;

reaching this code requires an explicit vers=1.0 mount.

Reject the response unless it is at least read_rsp_size bytes long. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97565
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97565