Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: zero pipe read compound padding

Compound response handling extends the last response iov to an eight-byte
boundary.

smb2_read_pipe() allocates only the payload size, so the alignment padding
can expose up to seven bytes of uninitialized kernel heap memory.

Allocate the aligned size and clear the unused tail before pinning the
response buffer.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

The ksmbd component of the Linux kernel contains a flaw in its SMB2 pipe read handling. The kernel allocates only the payload size for the response buffer but pads the last I/O vector to an eight‑byte boundary. This padding can expose up to seven bytes of uninitialized heap memory. When a client issues a padded read request, the server may return these uninitialized bytes, leaking internal kernel data that could reveal device identifiers, configuration information, or other sensitive state. The weakness stems from the improper handling of uninitialized memory, which can lead to information disclosure. It is a classic example of CWE‑254 (Uninitialized Memory Use) that also satisfies the criteria for CWE‑200 (Information Exposure). Because the leaked data is small, an attacker could still glean useful information through careful analysis of patterns or by correlating leaked bytes with known kernel structures.

Affected Systems

The vulnerability affects Linux kernel implementations that include the ksmbd SMB2 server component. The applicable product is the generic Linux kernel (Linux:Linux). No specific kernel version ranges are listed, so all kernel releases prior to the patch that contain ksmbd are potentially impacted.

Risk and Exploitability

The EPSS score is listed as less than 1%, indicating a very low probability of exploitation. The vulnerability is not present in the CISA KEV catalog, suggesting no known widespread exploitation at this time. The likely attack vector is over the network via the SMB2 protocol, requiring an attacker to have network access to the ksmbd service. The impact is limited to information disclosure, as the flaw does not provide privilege escalation or remote code execution.

Generated by OpenCVE AI on September 18, 2026 at 10:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel patch that allocates aligned memory for the response buffer and clears the unused tail before pinning the buffer.
  • Upgrade to a kernel version in which the ksmbd zero pipe read compound padding issue has been fixed.
  • If an immediate kernel update is unavailable, isolate the ksmbd service behind a network firewall to limit SMB traffic to trusted hosts.

Generated by OpenCVE AI on September 18, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-254

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: zero pipe read compound padding Compound response handling extends the last response iov to an eight-byte boundary. smb2_read_pipe() allocates only the payload size, so the alignment padding can expose up to seven bytes of uninitialized kernel heap memory. Allocate the aligned size and clear the unused tail before pinning the response buffer.
Title ksmbd: zero pipe read compound padding
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:25.592Z

Reserved: 2026-09-11T19:38:34.766Z

Link: CVE-2026-89794

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:44.197

Modified: 2026-09-16T11:16:44.197

Link: CVE-2026-89794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-254