Impact
A flaw in the Linux kernel’s CIF with a ByteCount of 0 or 1 as a signed integer, then uses the resulting huge size_t to copy a UTF‑16 string from a slab buffer. The bounds check in CIFS_STRNDUP_FROM_UTF16 is bypassed, causing an out‑of‑bounds read that leaks kernel memory contents into the debug file exposed under /proc/fs/cifs/DebugData. The weakness is a classic buffer over‑read (CWE‑125).
Affected Systems
All Linux kernel releases that include the CIFS SMB client and have not yet applied the fix are potentially vulnerable. This includes distributions that load the default CIFS module with a kernel prior to the patch delivery.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.1, reported as < 1 %, showing a very low but nonzero exploitation likelihood. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must control an SMB server to send a crafted tree‑connect response while the client accepts it. Once the exploit triggers, any user who can read /proc/fs/cifs/DebugData can obtain leaked kernel data, but the flaw provides no direct code execution or privilege escalation.
OpenCVE Enrichment