Description
In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix request buffer leak in smb2_new_read_req()

smb2_new_read_req() allocates the request buffer with
smb2_plain_req_init() but only publishes it to the caller with
*buf = req at the very end of the function. Two error returns sit in
between:

rc = smb2_plain_req_init(SMB2_READ, io_parms->tcon, server,
(void **) &req, total_len);
if (rc)
return rc;

if (server == NULL)
return -ECONNABORTED;
[...]
rdata->mr = smbd_register_mr(server->smbd_conn,
&rdata->subreq.io_iter,
true, need_invalidate);
if (!rdata->mr)
return -EAGAIN;

On either of them the buffer is neither released nor handed back, so
it is leaked. The caller cannot clean up after it: smb2_async_readv()
does 'goto out' on a non-zero return, which skips the
cifs_small_buf_release(buf) at async_readv_out, and buf has not been
assigned at that point in any case.

The write path has never had this problem. smb2_async_writev()
registers the memory region inline and jumps to its release label
instead of returning:

wdata->mr = smbd_register_mr(...);
if (!wdata->mr) {
rc = -EAGAIN;
goto async_writev_out;
}

Commit b7972092199f ("cifs: smbd: Retry on memory registration
failure") changed both sides from -ENOBUFS to -EAGAIN in a single
patch, which puts the two shapes next to each other.

Only the -EAGAIN return is reachable in practice, because
smb2_plain_req_init() calls smb2_reconnect() first and that already
fails with -EIO when server is NULL, before anything is allocated.
Both returns are given the same treatment here rather than leaving
one of them correct only by accident.

Because -EAGAIN is a replayable error, the failure also reaches the
retry block at the end of smb2_async_readv(), which marks the
subrequest NETFS_SREQ_NEED_RETRY, so a failing registration can be
retried rather than ending the I/O, and every attempt that reaches it
leaks another buffer. smb2_should_replay() short-circuits on
tcon->retry, so on a hard mount the attempt count is not bounded by
the retrans setting.

Only the asynchronous read path is affected. The synchronous
SMB2_read() caller passes rdata == NULL and the memory registration
block is guarded on rdata.

The memory registration failure path was pointed out by the Sashiko
AI reviewer while it was reviewing an unrelated patch to
smb2_async_readv().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak
Action: Update Kernel
AI Analysis

Impact

The vulnerability arises when the SMB client allocates a read request buffer but fails to release it during error paths, resulting in a memory leak. This occurs only in the asynchronous read operation, where an allocation error leads to the buffer being allocated and then never freed. The leaked buffers can accumulate, causing the kernel to exhaust available memory and potentially trigger an out‑of‑memory condition or service disruption. The weakness is a classic resource leak (CWE-401).

Affected Systems

The flaw exists in all Linux kernel versions that have not incorporated the patch identified by a set of commit hashes—including the patch that flushes the buffer during error returns. It is tied specifically to the SMB client read path (smb2_async_readv) and affects any system capable of executing SMB2 read requests, regardless of kernel distribution or release. Users of mainstream Linux distributions whose kernels are older than the one containing this fix remain vulnerable until they apply an updated kernel that includes the mentioned commits.

Risk and Exploitability

The EPSS score is reported to be less than 1 %, indicating a very low likelihood of real‑world exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is flooding SMB read requests designed to trigger memory registration failures, thereby inducing repeated EAGAIN errors that lead to the buffer leak. Because the flaw only manifests under error conditions (memory registration failure) and the SMB client would need to repeatedly trigger those errors, an attacker would need to craft SMB read traffic that causes repeated EAGAIN failures, which could be complex. Nonetheless, the unchecked leak could lead to memory exhaustion, so the risk is moderate if the flaw is triggered frequently. Administrators should treat this as a low‑to‑moderate risk until patched.

Generated by OpenCVE AI on September 18, 2026 at 23:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the commits b7972092199f and other related changes that release the buffer leak bug in smb2_new_read_req().
  • For systems unable to upgrade immediately, adjust SMB mount options to reduce retry attempts for memory registration failures, for example by setting a low retrans value or disabling hard mounts to limit repeated leaking.
  • Monitor kernel logs and memory usage for signs of repeated EAGAIN errors or excessive SMB read buffer allocation, and investigate any sudden increases in memory consumption or OOM killer activity.

Generated by OpenCVE AI on September 18, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-772

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb: client: fix request buffer leak in smb2_new_read_req() smb2_new_read_req() allocates the request buffer with smb2_plain_req_init() but only publishes it to the caller with *buf = req at the very end of the function. Two error returns sit in between: rc = smb2_plain_req_init(SMB2_READ, io_parms->tcon, server, (void **) &req, total_len); if (rc) return rc; if (server == NULL) return -ECONNABORTED; [...] rdata->mr = smbd_register_mr(server->smbd_conn, &rdata->subreq.io_iter, true, need_invalidate); if (!rdata->mr) return -EAGAIN; On either of them the buffer is neither released nor handed back, so it is leaked. The caller cannot clean up after it: smb2_async_readv() does 'goto out' on a non-zero return, which skips the cifs_small_buf_release(buf) at async_readv_out, and buf has not been assigned at that point in any case. The write path has never had this problem. smb2_async_writev() registers the memory region inline and jumps to its release label instead of returning: wdata->mr = smbd_register_mr(...); if (!wdata->mr) { rc = -EAGAIN; goto async_writev_out; } Commit b7972092199f ("cifs: smbd: Retry on memory registration failure") changed both sides from -ENOBUFS to -EAGAIN in a single patch, which puts the two shapes next to each other. Only the -EAGAIN return is reachable in practice, because smb2_plain_req_init() calls smb2_reconnect() first and that already fails with -EIO when server is NULL, before anything is allocated. Both returns are given the same treatment here rather than leaving one of them correct only by accident. Because -EAGAIN is a replayable error, the failure also reaches the retry block at the end of smb2_async_readv(), which marks the subrequest NETFS_SREQ_NEED_RETRY, so a failing registration can be retried rather than ending the I/O, and every attempt that reaches it leaks another buffer. smb2_should_replay() short-circuits on tcon->retry, so on a hard mount the attempt count is not bounded by the retrans setting. Only the asynchronous read path is affected. The synchronous SMB2_read() caller passes rdata == NULL and the memory registration block is guarded on rdata. The memory registration failure path was pointed out by the Sashiko AI reviewer while it was reviewing an unrelated patch to smb2_async_readv().
Title smb: client: fix request buffer leak in smb2_new_read_req()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:27.924Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90125

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:04.790

Modified: 2026-09-17T17:17:04.790

Link: CVE-2026-90125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:00:12Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-772

    Missing Release of Resource after Effective Lifetime