Out-of-bounds read in Linux kernel - CVE-2026-97563
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose kernel heap information or cause a denial of service.
The vulnerability exists due to insufficient validation of DataOffset in the CIFSSMBRead() SMB1 synchronous read helper when processing a crafted SMB1 read response. A remote attacker can return a response with a large DataOffset to read beyond the received response buffer and disclose adjacent kernel heap memory or trigger an oops.
Exploitation requires an explicitly configured SMB1 mount using vers=1.0, because SMB1 is not negotiated by default.