Description
In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()

reparse_buf_ptr() reads buf->ReparseDataLength before checking that
count covers the full fixed header:

buf = (struct reparse_data_buffer *)((u8 *)io + off);
len = sizeof(*buf); /* 8 bytes */
rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */

if (count < len || count < rdlen + len) /* check comes after */

struct reparse_data_buffer has ReparseDataLength at offset 4. If a
server returns OutputCount < 6, the read at offset 4-5 reaches past
the end of the received data. The off+count bounds against iov_len
were already validated, but that does not protect against count being
smaller than sizeof(*buf).

Split the check: verify count >= sizeof(*buf) before reading
ReparseDataLength, then verify count covers the data region.
Published: 2026-09-11
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Buffer Overread
Action: Apply Patch
AI Analysis

Impact

The Linux kernel SMB client contains a flaw where the function reparse_buf_ptr() reads the ReparseDataLength field from incoming SMB data before confirming that the buffer length is sufficient, resulting in a kernel buffer overread that can expose kernel memory contents or cause a crash if a malicious SMB server supplies a truncated response. impacts the confidentiality and integrity of data processed by the SMB client. Based on the description, it is inferred that the vulnerability can be triggered by a malicious SMB server response, allowing an attacker to manipulate the data sent to the client.

Affected Systems

All Linux kernel builds that include the SMB client code and have not incorporated the fix introduced in commit 05f78e6cf34ea3a285053bd5999e08e8ac298bd5 are vulnerable. The vulnerability remains in any kernel version where the buffer length check hasn’t been corrected, regardless of distribution or patch level. Administrators must verify the presence of the code change in their deployed kernel source or binary.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw can be triggered by malformed SMB server responses, making the attack vector network‑based. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of active exploitation, but any exposed system could experience information disclosure or denial of service if infected by a malicious SMB server. It is inferred that the attack vector is remote network‑based due to the involvement of the SMB protocol.

Generated by OpenCVE AI on September 15, 2026 at 21:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the SMB client check fix or apply the patch from commit 05f78e6cf34ea3a285053bd5999e08e8ac298bd5 to the kernel source and rebuild.
  • If upgrading is not immediately possible, restrict SMB traffic from untrusted networks or block inbound SMB connections to mitigate the attack surface.
  • Disable or uninstall the SMB client component if the environment does not require SMB functionality, thereby removing the vulnerable code path.

Generated by OpenCVE AI on September 15, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() reparse_buf_ptr() reads buf->ReparseDataLength before checking that count covers the full fixed header: buf = (struct reparse_data_buffer *)((u8 *)io + off); len = sizeof(*buf); /* 8 bytes */ rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */ if (count < len || count < rdlen + len) /* check comes after */ struct reparse_data_buffer has ReparseDataLength at offset 4. If a server returns OutputCount < 6, the read at offset 4-5 reaches past the end of the received data. The off+count bounds against iov_len were already validated, but that does not protect against count being smaller than sizeof(*buf). Split the check: verify count >= sizeof(*buf) before reading ReparseDataLength, then verify count covers the data region.
Title smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:32:11.058Z

Reserved: 2026-09-11T19:38:34.738Z

Link: CVE-2026-89632

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:48.763

Modified: 2026-09-13T07:17:28.300

Link: CVE-2026-89632

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:27Z

Links: CVE-2026-89632 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses