From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6F61C5867E5 for ; Fri, 11 Sep 2026 19:59:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156808; cv=none; b=fjC/SBfjDr7JtwdHZBAs0s95u0SPhDOZ5tEbziRl3ciNLsdgkkS8HITX8xCl9iwD3qyC09e1pVLnJG1nimWMIDgvnoOUTEqaQswlM4COXNeof2oBTWF8dt6xJYJsU1pqpcXytEf+NqymqBhpfHjdWbCfzIo07gyTSBFBJ5bBS3g= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156808; c=relaxed/simple; bh=7EX5hhko44alOtkivV2HxZ4xxKyoY2wrzQvqiKl/O8M=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=YslVxljsLLBjBFxhxomUJmDcARmebrxAljGL82jeURKPYRVesqU8NlPrEY2MfPaLKYlVuUKtOEiOTM+F3CrB3T12zkeY4VEh/8wPqNZaacF87lT0w14LIuBOLW2bvhzO7soFTGTmnZ8EAAz4tYrTX2Y7TYRuO0lWnKtIckGK4m4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=EMguytXl; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="EMguytXl" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 725FB1F00899; Fri, 11 Sep 2026 19:59:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156796; bh=h5JoVx2ab+EWY0pJKri/6sJFK6tpTz9HjmO95TjyWxI=; h=From:To:Cc:Subject:Date:Reply-To; b=EMguytXlIq/JnxdkPohhWoCTAm3GGy+TRNFrXSfF7I/baqeNOKgf6hiykK7zT8TR1 3aZzutgmD/c7YucA9Fgrm1N17O4YMvob2f/+2kT9O0UxWvOuMVG2+LmRckBGgGTfPX 5d0aI7aBvQs+s6NgF0YTNelcSNAa4DqULfT6uo9Y= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89637: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 Date: Fri, 11 Sep 2026 21:45:26 +0200 Message-ID: <2026091141-CVE-2026-89637-ca24@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2929; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=5NDT8N9uAP4MJdiAh07KwirH/hnshezIefg38rWpYKw=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIku9t3OpPrrJvLTGyqVlg51IcWbuXWOPZW36nxzeO P/fUbuiI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACZSt5phwVrjpnSNnU45bw13 pChPvmfzcGclN8OCbQuChU4+uFQU+XLh+8ltHc/TdrckAQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid->resp_buf with the new buffer (leaking the primary buffer) and, because mid->multiRsp is set, skips the server->smallbuf/bigbuf NULL-out. When the user thread frees mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid->multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid->resp_buf or the server buffer pointers. The Linux kernel CVE team has assigned CVE-2026-89637 to this issue. Affected and fixed versions =========================== Issue introduced in 3.6 with commit 316cf94a910f6f93d43cc574359d163ccae098a3 and fixed in 6.18.51 with commit 9eed72e9534b10a6d9f8f5146feff3db53aebdba Issue introduced in 3.6 with commit 316cf94a910f6f93d43cc574359d163ccae098a3 and fixed in 7.2.4 with commit 5e6533a683f6a851158d9f33fb4ea8f4f25d7f84 Issue introduced in 3.6 with commit 316cf94a910f6f93d43cc574359d163ccae098a3 and fixed in 7.3-rc1 with commit 730d0bb19507b9e19c2fe5343109ac618e2fbce5 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89637 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/smb/client/smb1transport.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9eed72e9534b10a6d9f8f5146feff3db53aebdba https://git.kernel.org/stable/c/5e6533a683f6a851158d9f33fb4ea8f4f25d7f84 https://git.kernel.org/stable/c/730d0bb19507b9e19c2fe5343109ac618e2fbce5