Description
In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()

coalesce_t2() computes data pointers directly from server-supplied
DataOffset fields with no validation against buffer bounds:

data_area_of_tgt = (char *)&pSMBt->hdr.Protocol +
get_unaligned_le16(&pSMBt->t2_rsp.DataOffset);
data_area_of_src = (char *)&pSMBs->hdr.Protocol +
get_unaligned_le16(&pSMBs->t2_rsp.DataOffset);
data_area_of_tgt += total_in_tgt;
...
memcpy(data_area_of_tgt, data_area_of_src, total_in_src);

A small DataOffset can push a pointer below the actual byte area,
overwriting header fields; a large one can push it past the buffer
end, causing out-of-bounds heap reads (source) or writes (target).
The BCC overflow guard does not prevent this: BCC reflects how much
data is present, while DataOffset controls where in the buffer it
starts.

The "validate target area" comment present since the function was
first written in 2005 was a placeholder that was never implemented.

Add lower- and upper-bound checks for both data pointers before the
memcpy, and before any target header fields are modified.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate patch
AI Analysis

Impact

The Linux kernel SMB client contains an out‑of‑bounds read/write flaw in the coalesce_t2() function, where data pointers are calculated directly from a server‑supplied DataOffset value without validating that the offset remains within the allocated buffer. A malicious SMB server can provide a carefully chosen offset that causes the target pointer to point outside the buffer boundaries, either below the buffer start to overwrite to trigger memory reads or writes outside the intended area. This overflow can corrupt kernel memory or redirect execution flow, enabling an attacker to gain arbitrary kernel code execution.

Affected Systems

All Linux kernel builds that include the original coalesce_t2() implementation and have not applied the patch are vulnerable. Because the vulnerable code resides in the core SMB client module, any distribution that ships the unpatched kernel—whether as a server or host functioning as an SMB client—may be affected. No specific kernel release list is provided, so every mainstream kernel version prior to the fix is potentially exposed.

Risk and Exploitability

The CVSS score of 9.8 classifies the flaw as critical. The EPSS score of <1% indicates a very low probability of exploitation, and there are no current public exploitation reports or entries in the CISA KEV catalog. However, exploitation would require a malicious SMB server capable of sending crafted DataOffset values to a target operating as an SMB client or external networks remain at higher risk.

Generated by OpenCVE AI on September 15, 2026 at 21:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that introduces bounds checks for DataOffset in coalesce_t2()
  • If the patch cannot be applied immediately, disable or restrict SMB client functionality on critical hosts until the kernel update is available
  • Configure firewall rules to block inbound SMB traffic from untrusted networks or limit SMB client connections to trusted ranges

Generated by OpenCVE AI on September 15, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() coalesce_t2() computes data pointers directly from server-supplied DataOffset fields with no validation against buffer bounds: data_area_of_tgt = (char *)&pSMBt->hdr.Protocol + get_unaligned_le16(&pSMBt->t2_rsp.DataOffset); data_area_of_src = (char *)&pSMBs->hdr.Protocol + get_unaligned_le16(&pSMBs->t2_rsp.DataOffset); data_area_of_tgt += total_in_tgt; ... memcpy(data_area_of_tgt, data_area_of_src, total_in_src); A small DataOffset can push a pointer below the actual byte area, overwriting header fields; a large one can push it past the buffer end, causing out-of-bounds heap reads (source) or writes (target). The BCC overflow guard does not prevent this: BCC reflects how much data is present, while DataOffset controls where in the buffer it starts. The "validate target area" comment present since the function was first written in 2005 was a placeholder that was never implemented. Add lower- and upper-bound checks for both data pointers before the memcpy, and before any target header fields are modified.
Title smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:32:12.305Z

Reserved: 2026-09-11T19:38:34.739Z

Link: CVE-2026-89633

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:48.887

Modified: 2026-09-13T07:17:28.413

Link: CVE-2026-89633

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:28Z

Links: CVE-2026-89633 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses