Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64448

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> smb: client: restrict implied bcc[0] exemption to responses without data area<br /> <br /> smb2_check_message() has a long-standing quirk that accepts a response<br /> whose calculated length is one byte larger than the bytes actually<br /> received ("server can return one byte more due to implied bcc[0]").<br /> This was introduced to accommodate servers that omit the trailing bcc[0]<br /> overlap byte when no data area is present.<br /> <br /> However, the exemption is applied unconditionally, regardless of whether<br /> the command actually carries a data area (has_smb2_data_area[]). When a<br /> response with a data area is subject to the +1 exemption, the reported<br /> data can extend one byte beyond the bytes actually received, yet<br /> smb2_check_message() still accepts it. The subsequent decoder then reads<br /> past the end of the receive buffer. This is reachable during NEGOTIATE<br /> and SESSION_SETUP, before the session is established.<br /> <br /> The resulting out-of-bounds reads are visible under KASAN when mounting<br /> against a non-conforming server; both the SPNEGO/negTokenInit and the<br /> NTLMSSP challenge decoders are affected:<br /> <br /> BUG: KASAN: slab-out-of-bounds in asn1_ber_decoder+0x16a7/0x1b00<br /> Read of size 1 at addr ffff8880084d67c0 by task mount.cifs/81<br /> CPU: 1 UID: 0 PID: 81 Comm: mount.cifs Not tainted 7.1.0-rc6 #1<br /> Call Trace:<br /> <br /> dump_stack_lvl+0x4e/0x70<br /> print_report+0x157/0x4c9<br /> kasan_report+0xce/0x100<br /> asn1_ber_decoder+0x16a7/0x1b00<br /> decode_negTokenInit+0x19/0x30<br /> SMB2_negotiate+0x31d9/0x4c90<br /> cifs_negotiate_protocol+0x1f2/0x3f0<br /> cifs_get_smb_ses+0x93f/0x17e0<br /> cifs_mount_get_session+0x7f/0x3a0<br /> cifs_mount+0xb4/0xcf0<br /> cifs_smb3_do_mount+0x23a/0x1500<br /> smb3_get_tree+0x3b0/0x630<br /> vfs_get_tree+0x82/0x2d0<br /> fc_mount+0x10/0x1b0<br /> path_mount+0x50d/0x1de0<br /> __x64_sys_mount+0x20b/0x270<br /> do_syscall_64+0xee/0x590<br /> entry_SYSCALL_64_after_hwframe+0x77/0x7f<br /> <br /> Allocated by task 85:<br /> kmem_cache_alloc_noprof+0x106/0x380<br /> mempool_alloc_noprof+0x116/0x1e0<br /> cifs_small_buf_get+0x31/0x80<br /> allocate_buffers+0x10d/0x2b0<br /> cifs_demultiplex_thread+0x1d5/0x1d50<br /> kthread+0x2c6/0x390<br /> ret_from_fork+0x36e/0x5a0<br /> ret_from_fork_asm+0x1a/0x30<br /> The buggy address is located 0 bytes to the right of<br /> allocated 448-byte region [ffff8880084d6600, ffff8880084d67c0)<br /> which belongs to the cache cifs_small_rq of size 448<br /> <br /> BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x36/0x50<br /> Read of size 329 at addr ffff88800726c678 by task mount.cifs/89<br /> CPU: 0 UID: 0 PID: 89 Comm: mount.cifs Tainted: G B 7.1.0-rc6 #1<br /> Call Trace:<br /> <br /> dump_stack_lvl+0x4e/0x70<br /> print_report+0x157/0x4c9<br /> kasan_report+0xce/0x100<br /> kasan_check_range+0x10f/0x1e0<br /> __asan_memcpy+0x23/0x60<br /> kmemdup_noprof+0x36/0x50<br /> decode_ntlmssp_challenge+0x457/0x680<br /> SMB2_sess_auth_rawntlmssp_negotiate+0x6f0/0xcb0<br /> SMB2_sess_setup+0x219/0x4f0<br /> cifs_setup_session+0x248/0xaf0<br /> cifs_get_smb_ses+0xf79/0x17e0<br /> cifs_mount_get_session+0x7f/0x3a0<br /> cifs_mount+0xb4/0xcf0<br /> cifs_smb3_do_mount+0x23a/0x1500<br /> smb3_get_tree+0x3b0/0x630<br /> vfs_get_tree+0x82/0x2d0<br /> fc_mount+0x10/0x1b0<br /> path_mount+0x50d/0x1de0<br /> __x64_sys_mount+0x20b/0x270<br /> do_syscall_64+0xee/0x590<br /> entry_SYSCALL_64_after_hwframe+0x77/0x7f<br /> <br /> Allocated by task 93:<br /> kmem_cache_alloc_noprof+0x106/0x380<br /> mempool_alloc_noprof+0x116/0x1e0<br /> cifs_small_buf_get+0x31/0x80<br /> allocate_buffers+0x10d/0x2b0<br /> cifs_demultiplex_thread+0x1d5/0x1d50<br /> kthread+0x2c6/0x390<br /> ret_from_fork+0x36e/0x5a0<br /> ret_from_fork_asm+0x1a/0x30<br /> The buggy address is located 120 bytes inside of<br /> allocated 448-byte region [ffff88800726c600, ffff88800726c7c0)<br /> which belongs to the cache cifs_small_rq of size 448<br /> <br /> Restrict the +1 exemption to responses that have no data area, so that<br /> it still covers the bcc[0] omission it was meant for. When a data area<br /> is present, the +1 discrepancy instead means the reported data length<br /> overruns the<br /> ---truncated---

Impacto