Out-of-bounds read in Linux kernel - CVE-2026-64448
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in smb2_check_message() and subsequent SMB client protocol decoders when processing crafted SMB2 responses with a data area. A remote attacker can send a specially crafted SMB server response to disclose sensitive information.
The issue is reachable during NEGOTIATE and SESSION_SETUP before the session is established, including through the SPNEGO/negTokenInit and NTLMSSP challenge decoders when mounting against a non-conforming server.
Affected software
How to mitigate CVE-2026-64448
External References
- https://git.kernel.org/stable/c/31c6312608c60b72a1feb99a5afb680645a3e8a3
- https://git.kernel.org/stable/c/419ec1b604d7fb60c10aec2dc062371f9fcd4940
- https://git.kernel.org/stable/c/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f
- https://git.kernel.org/stable/c/573e502d14714d2947e22e7eff40ec20a6a44a42
- https://git.kernel.org/stable/c/6e9d10f62773b99bd927940fd9cbdfe7207e23ff
- https://git.kernel.org/stable/c/8d0bbc78046d264bbf6a574ea6f9072258a43e35
- https://git.kernel.org/stable/c/b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0
- https://git.kernel.org/stable/c/ceb875a375dedbf51c9425c1d13a2d7a8435c08c