PT-2026-68079 · Linux · Linux Kernel
CVE-2026-64578
·
Published
2026-08-05
·
Updated
2026-08-09
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the ksmbd component where the
ksmbd smb2 check message() function reads the StructureSize2 field without verifying if the compound SMB2 request element is large enough to contain it. Because the logic only ensures a 64-byte header is present for the trailing element, a remote client can send a crafted compound request with a last element of exactly 64 bytes. This causes the 2-byte read at offset 64 to extend beyond the receive buffer, resulting in a slab-out-of-bounds read, which is a memory access that occurs outside the boundaries of a slab cache allocation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel