Description
In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix ALIGN() overflow in symlink_data() error context loop

The check added by commit 7d9a7f1f96cd ("smb/client: fix possible
infinite loop and oob read in symlink_data()") compared the post-ALIGN
length against the remaining buffer, but ALIGN() itself can overflow:
for ErrorDataLength near UINT32_MAX (e.g. 0xFFFFFFF9), ALIGN(x, 8)
wraps to 0, so the subsequent bounds check passes, and the loop
advances by zero bytes leaving 'p' pointing into stale data.

Fix by checking the raw ErrorDataLength against the remaining space
before applying ALIGN(), then checking again after. Since raw_len is
bounded by the buffer, raw_len + 7 cannot overflow, so the second check
is an exact post-alignment bounds guard.
Published: 2026-09-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read
Action: Patch
AI Analysis

Impact

This vulnerability occurs when the SMB client in the Linux kernel processes symlink error data whose length approaches the maximum 32‑bit value. The ALIGN() helper can wrap to zero during alignment, bypassing a boundary check and causing a loop that advances by zero bytes. The result is that the kernel reads outside the intended buffer (CWE‑125), potentially exposing arbitrary kernel memory contents or sensitive data to an attacker.

Affected Systems

All Linux kernel releases that have not incorporated commit 7d9a7f, which added the necessary bounds check, are affected. includes every distribution running a kernel older than the patch, regardless of vendor or distribution, as the defect resides in the core SMB client code used by all Linux systems.

Risk and Exploitability

With a CVSS score of 9.1, the vulnerability is rated very high. The EPSS score of <1% indicates a low current likelihood of exploitation. The CVE is not listed in the CISA KEV catalog, meaning no known public exploits. Based on the description, the most likely attack vector involves an SMB server sending an error packet with an successful exploitation would allow the kernel to read memory beyond the intended buffer, potentially leaking sensitive information. This inference is drawn from the mechanics of the overflow and the fact the bug is triggered by crafted error data.

Generated by OpenCVE AI on September 15, 2026 at 21:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains commit 7d9a7f, which implements the proper bounds checking for symlink error data.
  • If an immediate kernel update is not possible, disable SMB client support or block inbound SMB traffic on port 445 to prevent the vulnerable code from executing.
  • Continuously monitor system logs for anomalous SMB error handling activities that could indicate exploitation attempts.
  • Restrict SMB client usage to trusted networks only, for example by firewalling or segregating untrusted traffic.

Generated by OpenCVE AI on September 15, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb: client: fix ALIGN() overflow in symlink_data() error context loop The check added by commit 7d9a7f1f96cd ("smb/client: fix possible infinite loop and oob read in symlink_data()") compared the post-ALIGN length against the remaining buffer, but ALIGN() itself can overflow: for ErrorDataLength near UINT32_MAX (e.g. 0xFFFFFFF9), ALIGN(x, 8) wraps to 0, so the subsequent bounds check passes, and the loop advances by zero bytes leaving 'p' pointing into stale data. Fix by checking the raw ErrorDataLength against the remaining space before applying ALIGN(), then checking again after. Since raw_len is bounded by the buffer, raw_len + 7 cannot overflow, so the second check is an exact post-alignment bounds guard.
Title smb: client: fix ALIGN() overflow in symlink_data() error context loop
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:40.637Z

Reserved: 2026-09-11T19:38:34.739Z

Link: CVE-2026-89634

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:49.010

Modified: 2026-09-14T13:19:16.653

Link: CVE-2026-89634

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:28Z

Links: CVE-2026-89634 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses