๐Ÿ” CVE Alert

CVE-2026-89637

CRITICAL 9.8

smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid->resp_buf with the new buffer (leaking the primary buffer) and, because mid->multiRsp is set, skips the server->smallbuf/bigbuf NULL-out. When the user thread frees mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid->multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid->resp_buf or the server buffer pointers.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
316cf94a910f6f93d43cc574359d163ccae098a3 < 9eed72e9534b10a6d9f8f5146feff3db53aebdba 316cf94a910f6f93d43cc574359d163ccae098a3 < 5e6533a683f6a851158d9f33fb4ea8f4f25d7f84 316cf94a910f6f93d43cc574359d163ccae098a3 < 730d0bb19507b9e19c2fe5343109ac618e2fbce5
Linux / Linux
3.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9eed72e9534b10a6d9f8f5146feff3db53aebdba git.kernel.org: https://git.kernel.org/stable/c/5e6533a683f6a851158d9f33fb4ea8f4f25d7f84 git.kernel.org: https://git.kernel.org/stable/c/730d0bb19507b9e19c2fe5343109ac618e2fbce5