Impact
The ksmbd component of the Linux kernel contains a flaw in its SMB2 pipe read handling. The kernel allocates only the payload size for the response buffer but pads the last I/O vector to an eight‑byte boundary. This padding can expose up to seven bytes of uninitialized heap memory. When a client issues a padded read request, the server may return these uninitialized bytes, leaking internal kernel data that could reveal device identifiers, configuration information, or other sensitive state. The weakness stems from the improper handling of uninitialized memory, which can lead to information disclosure. It is a classic example of CWE‑254 (Uninitialized Memory Use) that also satisfies the criteria for CWE‑200 (Information Exposure). Because the leaked data is small, an attacker could still glean useful information through careful analysis of patterns or by correlating leaked bytes with known kernel structures.
Affected Systems
The vulnerability affects Linux kernel implementations that include the ksmbd SMB2 server component. The applicable product is the generic Linux kernel (Linux:Linux). No specific kernel version ranges are listed, so all kernel releases prior to the patch that contain ksmbd are potentially impacted.
Risk and Exploitability
The EPSS score is listed as less than 1%, indicating a very low probability of exploitation. The vulnerability is not present in the CISA KEV catalog, suggesting no known widespread exploitation at this time. The likely attack vector is over the network via the SMB2 protocol, requiring an attacker to have network access to the ksmbd service. The impact is limited to information disclosure, as the flaw does not provide privilege escalation or remote code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA