Impact
This vulnerability occurs when the SMB client in the Linux kernel processes symlink error data whose length approaches the maximum 32‑bit value. The ALIGN() helper can wrap to zero during alignment, bypassing a boundary check and causing a loop that advances by zero bytes. The result is that the kernel reads outside the intended buffer (CWE‑125), potentially exposing arbitrary kernel memory contents or sensitive data to an attacker.
Affected Systems
All Linux kernel releases that have not incorporated commit 7d9a7f, which added the necessary bounds check, are affected. includes every distribution running a kernel older than the patch, regardless of vendor or distribution, as the defect resides in the core SMB client code used by all Linux systems.
Risk and Exploitability
With a CVSS score of 9.1, the vulnerability is rated very high. The EPSS score of <1% indicates a low current likelihood of exploitation. The CVE is not listed in the CISA KEV catalog, meaning no known public exploits. Based on the description, the most likely attack vector involves an SMB server sending an error packet with an successful exploitation would allow the kernel to read memory beyond the intended buffer, potentially leaking sensitive information. This inference is drawn from the mechanics of the overflow and the fact the bug is triggered by crafted error data.
OpenCVE Enrichment
Debian DSA