Impact
The vulnerability stems from a logic error in the SMB client’s data offset validation routine. A counter that should bound the DataOffset field became zero after a wrap‑around subtraction, disabling the bounds check. The result is an out‑of‑bounds read (CWE‑125), allowing an attacker to read bytes beyond the intended buffer in the Linux kernel, potentially exposing kernel memory contents or causing a crash.
Affected Systems
All Linux kernel implementations that contain the buggy code sequence before the fix commit were susceptible. The advisory does not list specific kernel releases; any kernel that incorporates the commits that introduced the bug remains vulnerable until the patch commit restoring proper bounds checking is applied.
Risk and Exploitability
The CVSS score of 9.1 places the vulnerability in the high severity zone, while the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed public exploits. Attackers would need to craft a specially structured SMB packet, implying a remote SMB attack vector. Despite the low EPSS probability and lack of KEV listing, the potential impact remains significant should an exploit be discovered, so prompt patching is required.
OpenCVE Enrichment