Impact
A malformed secondary SMB transaction can trigger a use‑after‑free in the Linux kernel’s CIFS (SMB) client. When a a subsequent malformed secondary response causes cifs_check_trans2() to return false due to an invalid SMB header or a rejected PDU, the client logic new buffer, leaving server->smallbuf/bigbuf dangling. The demultiplexer thread later reuses that memory for the next packet, creating a dangling pointer that can be exploited. The flaw arises from improper handling of buffer references and is identified by CWE‑825.
Affected Systems
The flaw resides in the Linux kernel’s CIFS (SMB) client implementation. Any kernel that includes CIFS client support and lacks the patch applied in the recent commit is vulnerable. Versions preceding the patched release are at risk until updated.
Risk and Exploitability
The CVSS score is 9.8, indicating catastrophic is < 1%, implying a very low exploitation probability under current threat landscape. The vulnerability is not listed in CISA's KEV catalog. The CVE description indicates a use‑after‑free is triggered by malformed secondary SMB responses. Based on the description, it is inferred that an attacker could send crafted SMB replies from a malicious SMB server to a vulnerable client over the network, exposing only systems that accept SMB traffic. be treated as high risk, albeit with low likelihood of exploitation.
OpenCVE Enrichment