Impact
The Linux kernel SMB client contains a flaw where the function reparse_buf_ptr() reads the ReparseDataLength field from incoming SMB data before confirming that the buffer length is sufficient, resulting in a kernel buffer overread that can expose kernel memory contents or cause a crash if a malicious SMB server supplies a truncated response. impacts the confidentiality and integrity of data processed by the SMB client. Based on the description, it is inferred that the vulnerability can be triggered by a malicious SMB server response, allowing an attacker to manipulate the data sent to the client.
Affected Systems
All Linux kernel builds that include the SMB client code and have not incorporated the fix introduced in commit 05f78e6cf34ea3a285053bd5999e08e8ac298bd5 are vulnerable. The vulnerability remains in any kernel version where the buffer length check hasn’t been corrected, regardless of distribution or patch level. Administrators must verify the presence of the code change in their deployed kernel source or binary.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw can be triggered by malformed SMB server responses, making the attack vector network‑based. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of active exploitation, but any exposed system could experience information disclosure or denial of service if infected by a malicious SMB server. It is inferred that the attack vector is remote network‑based due to the involvement of the SMB protocol.
OpenCVE Enrichment