Feed
Linux Kernel

A stranger can make the kernel SMB server read past a short packet

Brief

It is not in 7.1.8.

Notes

cfc0b8e5080aec87700774e8568765eaa4b7b92b (Namjae Jeon). Fixes: 368ba06881c3. Cc: stable.

A transform packet skipped the minimum SMB2 size check. On SMB 2.1 a short one read past the request.

Later confirm: CVE-2026-68431. Not in 7.1.8. The commit does not say privilege escalation.

Commit cfc0b8e5080aec87700774e8568765eaa4b7b92b

Sources