SB2026081674 - Integer overflow in Linux kernel cifs
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-72310)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an integer overflow in smb2_ioctl_query_info() when validating a PASSTHRU_FSCTL response payload from a malicious server. A remote attacker can send a specially crafted server response to disclose sensitive information.
The out-of-bounds read occurs during a later copy_to_user() operation after a wrapped offset-plus-length check passes.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/160045fc943f6c46b227644261252c8a22b8a87a
- https://git.kernel.org/stable/c/1627e7d5c9b09721a141d07cedb178882f1ded67
- https://git.kernel.org/stable/c/175357ee0c596cb82054650dfa32fda51ad35aaa
- https://git.kernel.org/stable/c/1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9
- https://git.kernel.org/stable/c/63feb687e89a3a52a31e6e01764117cc500f1974
- https://git.kernel.org/stable/c/a4f27ad055392fa164f5649e89a3637b033c5fcc
- https://git.kernel.org/stable/c/b30771b69eafae750afb7385fbcc3d77ed3f3670
- https://git.kernel.org/stable/c/dbd126539c098dba3159ce7d34b10b2daddcbd0f