A stranger can make the kernel SMB server read past a short packet
Brief
It is not in 7.1.8.
Notes
cfc0b8e5080aec87700774e8568765eaa4b7b92b (Namjae Jeon). Fixes: 368ba06881c3. Cc: stable.
A transform packet skipped the minimum SMB2 size check. On SMB 2.1 a short one read past the request.
Later confirm: CVE-2026-68431. Not in 7.1.8. The commit does not say privilege escalation.
Commit cfc0b8e5080aec87700774e8568765eaa4b7b92b