CVE-2026-64448
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
smb: client: restrict implied bcc[0] exemption to responses without data area<br />
<br />
smb2_check_message() has a long-standing quirk that accepts a response<br />
whose calculated length is one byte larger than the bytes actually<br />
received ("server can return one byte more due to implied bcc[0]").<br />
This was introduced to accommodate servers that omit the trailing bcc[0]<br />
overlap byte when no data area is present.<br />
<br />
However, the exemption is applied unconditionally, regardless of whether<br />
the command actually carries a data area (has_smb2_data_area[]). When a<br />
response with a data area is subject to the +1 exemption, the reported<br />
data can extend one byte beyond the bytes actually received, yet<br />
smb2_check_message() still accepts it. The subsequent decoder then reads<br />
past the end of the receive buffer. This is reachable during NEGOTIATE<br />
and SESSION_SETUP, before the session is established.<br />
<br />
The resulting out-of-bounds reads are visible under KASAN when mounting<br />
against a non-conforming server; both the SPNEGO/negTokenInit and the<br />
NTLMSSP challenge decoders are affected:<br />
<br />
BUG: KASAN: slab-out-of-bounds in asn1_ber_decoder+0x16a7/0x1b00<br />
Read of size 1 at addr ffff8880084d67c0 by task mount.cifs/81<br />
CPU: 1 UID: 0 PID: 81 Comm: mount.cifs Not tainted 7.1.0-rc6 #1<br />
Call Trace:<br />
<br />
dump_stack_lvl+0x4e/0x70<br />
print_report+0x157/0x4c9<br />
kasan_report+0xce/0x100<br />
asn1_ber_decoder+0x16a7/0x1b00<br />
decode_negTokenInit+0x19/0x30<br />
SMB2_negotiate+0x31d9/0x4c90<br />
cifs_negotiate_protocol+0x1f2/0x3f0<br />
cifs_get_smb_ses+0x93f/0x17e0<br />
cifs_mount_get_session+0x7f/0x3a0<br />
cifs_mount+0xb4/0xcf0<br />
cifs_smb3_do_mount+0x23a/0x1500<br />
smb3_get_tree+0x3b0/0x630<br />
vfs_get_tree+0x82/0x2d0<br />
fc_mount+0x10/0x1b0<br />
path_mount+0x50d/0x1de0<br />
__x64_sys_mount+0x20b/0x270<br />
do_syscall_64+0xee/0x590<br />
entry_SYSCALL_64_after_hwframe+0x77/0x7f<br />
<br />
Allocated by task 85:<br />
kmem_cache_alloc_noprof+0x106/0x380<br />
mempool_alloc_noprof+0x116/0x1e0<br />
cifs_small_buf_get+0x31/0x80<br />
allocate_buffers+0x10d/0x2b0<br />
cifs_demultiplex_thread+0x1d5/0x1d50<br />
kthread+0x2c6/0x390<br />
ret_from_fork+0x36e/0x5a0<br />
ret_from_fork_asm+0x1a/0x30<br />
The buggy address is located 0 bytes to the right of<br />
allocated 448-byte region [ffff8880084d6600, ffff8880084d67c0)<br />
which belongs to the cache cifs_small_rq of size 448<br />
<br />
BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x36/0x50<br />
Read of size 329 at addr ffff88800726c678 by task mount.cifs/89<br />
CPU: 0 UID: 0 PID: 89 Comm: mount.cifs Tainted: G B 7.1.0-rc6 #1<br />
Call Trace:<br />
<br />
dump_stack_lvl+0x4e/0x70<br />
print_report+0x157/0x4c9<br />
kasan_report+0xce/0x100<br />
kasan_check_range+0x10f/0x1e0<br />
__asan_memcpy+0x23/0x60<br />
kmemdup_noprof+0x36/0x50<br />
decode_ntlmssp_challenge+0x457/0x680<br />
SMB2_sess_auth_rawntlmssp_negotiate+0x6f0/0xcb0<br />
SMB2_sess_setup+0x219/0x4f0<br />
cifs_setup_session+0x248/0xaf0<br />
cifs_get_smb_ses+0xf79/0x17e0<br />
cifs_mount_get_session+0x7f/0x3a0<br />
cifs_mount+0xb4/0xcf0<br />
cifs_smb3_do_mount+0x23a/0x1500<br />
smb3_get_tree+0x3b0/0x630<br />
vfs_get_tree+0x82/0x2d0<br />
fc_mount+0x10/0x1b0<br />
path_mount+0x50d/0x1de0<br />
__x64_sys_mount+0x20b/0x270<br />
do_syscall_64+0xee/0x590<br />
entry_SYSCALL_64_after_hwframe+0x77/0x7f<br />
<br />
Allocated by task 93:<br />
kmem_cache_alloc_noprof+0x106/0x380<br />
mempool_alloc_noprof+0x116/0x1e0<br />
cifs_small_buf_get+0x31/0x80<br />
allocate_buffers+0x10d/0x2b0<br />
cifs_demultiplex_thread+0x1d5/0x1d50<br />
kthread+0x2c6/0x390<br />
ret_from_fork+0x36e/0x5a0<br />
ret_from_fork_asm+0x1a/0x30<br />
The buggy address is located 120 bytes inside of<br />
allocated 448-byte region [ffff88800726c600, ffff88800726c7c0)<br />
which belongs to the cache cifs_small_rq of size 448<br />
<br />
Restrict the +1 exemption to responses that have no data area, so that<br />
it still covers the bcc[0] omission it was meant for. When a data area<br />
is present, the +1 discrepancy instead means the reported data length<br />
overruns the<br />
---truncated---
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/31c6312608c60b72a1feb99a5afb680645a3e8a3
- https://git.kernel.org/stable/c/419ec1b604d7fb60c10aec2dc062371f9fcd4940
- https://git.kernel.org/stable/c/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f
- https://git.kernel.org/stable/c/573e502d14714d2947e22e7eff40ec20a6a44a42
- https://git.kernel.org/stable/c/6e9d10f62773b99bd927940fd9cbdfe7207e23ff
- https://git.kernel.org/stable/c/8d0bbc78046d264bbf6a574ea6f9072258a43e35
- https://git.kernel.org/stable/c/b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0
- https://git.kernel.org/stable/c/ceb875a375dedbf51c9425c1d13a2d7a8435c08c



