Impact
The Linux kernel SMB client contains an out‑of‑bounds read/write flaw in the coalesce_t2() function, where data pointers are calculated directly from a server‑supplied DataOffset value without validating that the offset remains within the allocated buffer. A malicious SMB server can provide a carefully chosen offset that causes the target pointer to point outside the buffer boundaries, either below the buffer start to overwrite to trigger memory reads or writes outside the intended area. This overflow can corrupt kernel memory or redirect execution flow, enabling an attacker to gain arbitrary kernel code execution.
Affected Systems
All Linux kernel builds that include the original coalesce_t2() implementation and have not applied the patch are vulnerable. Because the vulnerable code resides in the core SMB client module, any distribution that ships the unpatched kernel—whether as a server or host functioning as an SMB client—may be affected. No specific kernel release list is provided, so every mainstream kernel version prior to the fix is potentially exposed.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical. The EPSS score of <1% indicates a very low probability of exploitation, and there are no current public exploitation reports or entries in the CISA KEV catalog. However, exploitation would require a malicious SMB server capable of sending crafted DataOffset values to a target operating as an SMB client or external networks remain at higher risk.
OpenCVE Enrichment