CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix next buffer leak in receiveencryptedstandard()
receiveencryptedstandard() allocates nextbuffer before checking whether the number of compound PDUs already reached MAXCOMPOUND. If the limit check fails, the function returns immediately and the newly allocated nextbuffer is not assigned to server->smallbuf/server->bigbuf, making it leaked.
Move the MAXCOMPOUND check before allocating nextbuffer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the Linux kernel so that the MAX_COMPOUND limit check is performed before allocating next_buffer in receive_encrypted_standard() (fixes the next_buffer leak when the MAX_COMPOUND check fails and the function returns immediately).
Linux kernel MAX_COMPOUND check placement = Move MAX_COMPOUND check before allocating next_buffer
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel SMB client are exposed when they process encrypted SMB responses that reach the compound-PDU limit in receive_encrypted_standard(). The provided data does not identify affected kernel versions or configuration defaults.
What access does an attacker need to exploit it?
The CVSS vector indicates local attack access and low privileges, with no user interaction required. The issue is a memory leak caused by the SMB client code returning after the compound-PDU limit check without retaining the allocated buffer.
What is the impact of successful exploitation?
The supplied CVSS score is 7.8 High and rates confidentiality, integrity, and availability impacts as High. The specific defect described is a leaked next_buffer allocation.
What is the remediation?
Apply a Linux kernel update containing the fix that performs the MAX_COMPOUND limit check before allocating next_buffer. The listed stable-kernel references identify commits carrying the fix.