-

CVE-2026-97560

smb: client: fix one-byte OOB read in smb2_parse_native_symlink()

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix one-byte OOB read in smb2_parse_native_symlink()

When parsing a share-root relative native symlink, memcpy copies
smb_target+1 (skipping the leading separator) but uses
strlen(smb_target)+1 as the length, reading one byte past the
allocated buffer.

This fixes the following KASAN splat when accessing an SMB symlink
with a target of '\a\b':

  BUG: KASAN: slab-out-of-bounds in smb2_parse_native_symlink+0x4f5/0xca0
  Read of size 5 at addr ffff88800878fe21 by task netfsfuzz-execu/1
  CPU: 1 UID: 0 PID: 1 Comm: netfsfuzz-execu Tainted: G N
  7.2.0-11943-g2709dd5ae32f-dirty #1 PREEMPT(lazy)
  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix,
  1996)
  Call Trace:
   <TASK>
   dump_stack_lvl+0x7b/0xa0
   print_report+0xd0/0x630
   kasan_report+0xe5/0x120
   kasan_check_range+0x105/0x1b0
   __asan_memcpy+0x23/0x60
   smb2_parse_native_symlink+0x4f5/0xca0
   parse_reparse_point+0x68a/0x1530
   reparse_info_to_fattr+0x752/0xa20
   cifs_get_fattr+0x873/0x15b0
   cifs_get_inode_info+0xc0/0x310
   cifs_lookup+0x308/0xa70
   __lookup_slow+0x122/0x2b0
   lookup_slow+0x50/0x70
   path_lookupat+0x525/0xaf0
   filename_lookup+0x1f2/0x550
   vfs_statx+0xd1/0x1a0
   vfs_fstatat+0x65/0xc0
   __do_sys_newfstatat+0x9a/0x120
   do_syscall_64+0xdd/0x4a0
   entry_SYSCALL_64_after_hwframe+0x77/0x7f
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 430afd3edabf942a908570e5a41414bb455f15f8
Version < ff411fcbfc55eec1d66ea82483d254319dc8e973
Status affected
Version fc5a409552be479715b147748f2f61b41b512976
Version < 22a9d0a9ba0c89be57558c1aa80dc60a571dd89c
Status affected
Version 723f4ef90452aa629f3d923e92e0449d69362b1d
Version < d1f173d28e964ba2c3c4ebe7491d594dc8c77a40
Status affected
Version 723f4ef90452aa629f3d923e92e0449d69362b1d
Version < 2a302fdbaf7dd00d285303c94af8f48321c22993
Status affected
Version 723f4ef90452aa629f3d923e92e0449d69362b1d
Version < cb26524ef4ac28fcfa554c0656e8dc412c38a8ff
Status affected
Version c9280c017ea13ff8678ef4f1ea78a4b683292e8b
Status affected
Version 6.6.64
Version < 6.6.158
Status affected
Version 6.12.2
Version < 6.12.111
Status affected
Version 6.11.11
Version < 6.12
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.13
Status affected
Version 0
Version < 6.13
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/22a9d0a9ba0c89be57558c1aa80dc60a571dd89c
https://git.kernel.org/stable/c/d1f173d28e964ba2c3c4ebe7491d594dc8c77a40
https://git.kernel.org/stable/c/2a302fdbaf7dd00d285303c94af8f48321c22993
https://git.kernel.org/stable/c/cb26524ef4ac28fcfa554c0656e8dc412c38a8ff
https://git.kernel.org/stable/c/ff411fcbfc55eec1d66ea82483d254319dc8e973