Linux kernel ksmbd OOB read in SMB2 compound request
CVE-2026-64578 Published on August 5, 2026
ksmbd: validate compound request size before reading StructureSize2
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate compound request size before reading StructureSize2
When ksmbd validates a compound (chained) SMB2 request,
ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
checking that the compound element is large enough to contain it.
StructureSize2 is a 2-byte field at offset 64
(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.
The compound-walking logic only guarantees that a full 64-byte SMB2
header is present for the trailing element: when NextCommand is 0, len is
reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A
remote client can craft a compound request whose last element has exactly
64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte
past the receive buffer, producing a slab-out-of-bounds read.
BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14
The buggy address is located 172 bytes inside of allocated 173-byte region
Workqueue: ksmbd-io handle_ksmbd_work
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
handle_ksmbd_work (fs/smb/server/server.c:119)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3397)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Reject any compound element that is too small to hold StructureSize2
before dereferencing it.
Products Associated with CVE-2026-64578
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 and below 2c307126ed8e7adddab82b8e31d962d3a2156ab1 is affected.
- Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 and below f7550a91ab211726f59cb137523b7a9eae1ac6eb is affected.
- Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 and below f0e337e7db67cc1c832958bbb6c4026bdceacfdb is affected.
- Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 and below ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a is affected.
- Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 and below 15b38176fd1530372905c602fde51fe89ec8c877 is affected.
- Version 5.15 is affected.
- Before 5.15 is unaffected.
- Version 6.6.148, <= 6.6.* is unaffected.
- Version 6.12.101, <= 6.12.* is unaffected.
- Version 6.18.42, <= 6.18.* is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc4, <= * is unaffected.