From: AL-KERNEL <[email protected]>
To: [email protected]
Subject: [CVE-2026-52967][MODERATE 7.0] smb/client: fix possible infinite loop and oob read in symlink_data()
Date: Wed, 24 Jun 2026 15:27:53 -0400 [thread overview]
Message-ID: <[email protected]> (raw)
CVE: CVE-2026-52967
Priority: MODERATE 7.0
AL-KERNEL base severity: MODERATE
KPANIC flag: NO
Patch: smb/client: fix possible infinite loop and oob read in symlink_data()
Commit: 1cfa2d59f669db28d6292d10ff87ca6837c781b0
Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1cfa2d59f669db28d6292d10ff87ca6837c781b0
Original CVE announcement: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-52967
Analysis date: Wed, 24 Jun 2026 15:27:53 -0400
ActionableScore: 5
ActionableScore lower bound: 3
Actionable bucket: Actionable Moderate at minimum
Manual review required: YES
Summary:
A malicious SMB server can craft an SMB2 symlink error context with a large ErrorDataLength value that causes pointer wraparound on 32-bit clients, leading to an infinite loop or out-of-bounds read and resulting primarily in client-side denial of service.
======================================================================
ABOUT THIS REPORT
======================================================================
The original Linux kernel CVE announcement for CVE-2026-52967 is available here:
https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-52967
The original announcement does not normally provide a security severity
estimate, CVSS assessment, or enough information to determine whether the
reported kernel bug represents a practically relevant security issue.
This report was generated by AL-KERNEL, an AI-assisted Linux kernel
vulnerability analysis system developed by Alexander Larkin. It combines
an autonomous classifier with LLM-assisted technical analysis and a
separate ActionableScore mechanism.
The purpose of this report is to prioritize Linux kernel CVEs before
manual review, identify cases that require prompt investigation, and
support automatic closure of issues that are unlikely to have meaningful
security impact.
Published priority for this report: MODERATE 7.0
Manual review required: YES
A detailed explanation of the methodology and priority rules is included
at the end of this message.
======================================================================
AL-KERNEL CLASSIFICATION RESULT
======================================================================
CVE-2026-52967 MODERATE CHECK Maybe valid. Check manually. Hints by AL-KERNEL: The best (paranoid) CVSS is 'AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H';CWE-125;*CWE-835;CWE-190;*CWE-20;Other CVSS 'AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H';BEST CVSS score: '7.1';DESCR 'An SMB2 client side parser bug in symlink_data() can be triggered by a malicious or compromised SMB server returning a crafted symlink error context with a very large ErrorDataLength value. On 32-bit architectures this value can wrap pointer arithmetic when the client advances to the next error context, causing either an infinite loop or an out-of-bounds read before the response buffer. For the CVSS the PR:N is used because the attacker does not need privileges on the victim system, but the victim client must connect to or use an attacker controlled SMB server. The issue is network reachable from the server side, but UI:R is used because the victim normally has to mount or access the SMB share. Impact is primarily denial of service via client hang or kernel crash. The paranoid score adds C:L because the bug includes an OOB read primitive, but no write primitive or direct privilege escalation path is evident.';YES REQUIRES MANUAL CHECK; ,and ActionableScore result is Actionable Moderate at minimum (with actual score 4) YES OOB DISK SIMPLEFIX HARDWARE SERVERTOCLIENT DECREASED_TO_MODERATEREG_BASED_ON_ACTIONABLESCORELESSTHAN5 NO NO checked
======================================================================
ACTIONABLESCORE ANALYSIS
======================================================================
ActionableScore=5
ActionableScoreLower=3
## 1. ActionableScore
* Conservative score: 3
* Paranoid score: 5
* Final recommended bucket: **Actionable Moderate at minimum**
## 2. Signal breakdown
Conservative signals:
* Remote reachable / network-triggerable: +2
A malicious or compromised SMB server can send a crafted SMB2 symlink error response to the client.
* Reliable kernel crash / strong DoS: +1
The commit explicitly describes an infinite loop on 32-bit architectures. This is a credible availability issue.
* Broad/default/common subsystem: +1
SMB/CIFS client support is a commonly deployed filesystem client path, though exploitation requires the client to connect to the attacker-controlled server.
* Rare/configuration-dependent condition: -1
The described pointer wraparound requires 32-bit architectures, which limits practical exposure on modern general-purpose deployments.
Paranoid additional signals:
* Confidentiality impact plausible: +1
The bug includes an out-of-bounds read condition. No direct disclosure channel is demonstrated, but the parser may consume data outside the intended response buffer, so limited confidentiality concern is defensible for triage.
* No 32-bit exposure penalty in paranoid score: +1 effective difference
For supported 32-bit systems using SMB mounts, the trigger is realistic once a malicious server is contacted, so the paranoid score treats the architecture condition as limiting but not sufficient for auto-close.
Not counted:
* No generic strong memory corruption.
The patch shows OOB read and infinite loop, not OOB write, UAF, double-free, arbitrary write, or type confusion.
* No privilege escalation bonus.
There is no demonstrated reclaim, overwrite, callback control, refcount takeover, or write primitive.
* No Dirty-Pipe-like or page-cache corruption signal.
The issue is response parsing, not shared page or file-backed cache corruption.
## 3. Reachability analysis
The attacker is most realistically a malicious SMB server, compromised SMB server, or network attacker able to tamper with SMB responses. The victim must mount or access an SMB share that returns a crafted symlink error context. No local privileges on the victim are required by the attacker, but user interaction or preexisting mount usage is typically needed.
Namespaces and containers do not substantially lower the attacker requirement unless a containerized workload can force the host or a privileged helper to access the malicious SMB share. The affected path is not packet-processing on unsolicited inbound traffic. It is client-side network parsing after an SMB session or share access.
The main practical limiter is the 32-bit architecture condition. On affected 32-bit clients, the exploitability for DoS appears straightforward once the client processes the crafted response.
## 4. Severity interpretation
This behaves more like an actionable Moderate than an ordinary Moderate because it is network-delivered from an SMB server and includes both an infinite-loop condition and an OOB read condition. It is not an Important-class memory corruption issue based on the patch alone, because there is no write primitive, UAF, object lifetime corruption, or credible privilege escalation path.
The conservative score is lower due to the 32-bit limitation and lack of demonstrated disclosure. The paranoid score is higher because network-delivered filesystem client parsers with OOB reads should not be auto-closed without manual review.
## 5. One-sentence report phrase
A malicious SMB server can craft an SMB2 symlink error context with a large ErrorDataLength value that causes pointer wraparound on 32-bit clients, leading to an infinite loop or out-of-bounds read and resulting primarily in client-side denial of service.
## 6. Manual review recommendation
MANUAL CHECK REQUIRED
Reason: this is a network-triggered SMB client parser bug with an explicit OOB read condition, even though practical impact appears limited mainly to DoS on 32-bit systems.
======================================================================
UPSTREAM PATCH SUMMARY
======================================================================
Patch: smb/client: fix possible infinite loop and oob read in symlink_data()
Commit: 1cfa2d59f669db28d6292d10ff87ca6837c781b0
Upstream URL: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1cfa2d59f669db28d6292d10ff87ca6837c781b0
Commit description:
On 32-bit architectures, the infinite loop is as follows:
len = p->ErrorDataLength == 0xfffffff8
u8 *next = p->ErrorContextData + len
next == p
On 32-bit architectures, the out-of-bounds read is as follows:
len = p->ErrorDataLength == 0xfffffff0
u8 *next = p->ErrorContextData + len
next == (u8 *)p - 8
Reported-by: ChenXiaoSong <[email protected]>
Fixes: 76894f3 ("cifs: improve symlink handling for smb2+")
Cc: [email protected]
Signed-off-by: Ye Bin <[email protected]>
Reviewed-by: ChenXiaoSong <[email protected]>
Signed-off-by: Steve French <[email protected]>
Signed-off-by: Greg Kroah-Hartman <[email protected]>
Changed files:
fs/smb/client/smb2file.c
Diff excerpt:
Not included in this email. See the upstream URL for the full patch.
Full patch:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1cfa2d59f669db28d6292d10ff87ca6837c781b0
======================================================================
DETAILED REPORT METHODOLOGY
======================================================================
The original Linux kernel CVE announcement for CVE-2026-52967 can be found here:
https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-52967
The original CVE announcement normally does not include a security-level
estimate. In particular, it may not contain a CVSS assessment, an impact
level, or enough information to determine whether the reported bug is a
practically relevant security issue. One purpose of this parallel CVE list
is to provide that missing technical and prioritization information.
The original goal of the AL-KERNEL project was to prioritize Linux kernel
CVE analysis automatically before manual review. The system can also help
identify non-security issues that may be suitable for automatic closure.
This report was generated by AL-KERNEL, an AI-assisted Linux kernel
vulnerability analysis system developed by Alexander Larkin.
The first analysis stage combines an autonomous classifier with additional
LLM-based analysis. The autonomous classifier runs locally on a CPU and is
based on a backpropagation neural network. Together, these mechanisms
produce a technical vulnerability description, identify likely weakness
types, estimate CVSS severity, and provide input for ActionableScore.
Two CVSS estimates are retained because incomplete kernel vulnerability
information often permits more than one defensible interpretation:
Conservative CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The Best / paranoid CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
The Best / paranoid CVSS score: 7.1
The conservative vector represents a lower-impact interpretation.
The Best/paranoid vector intentionally represents a plausible upper-bound
interpretation and should not automatically be treated as demonstrated
real-world impact.
CVSS may also need to be adjusted for a particular Linux deployment,
because actual reachability, privileges, enabled kernel configuration,
hardware, namespaces, exposed device nodes, and other environmental
conditions can differ significantly between systems.
A separate ActionableScore mechanism evaluates practical remediation
urgency. Its analysis may include reachability, attack prerequisites,
subsystem exposure, memory-corruption characteristics, denial-of-service
reliability, and possible confidentiality, integrity, or
privilege-escalation impact.
Conservative ActionableScore: 3
Paranoid ActionableScore: 5
The final base severity is taken directly from the second tab-separated
field of the AL-KERNEL classification result. ActionableScore does not
replace or independently override that final AL-KERNEL decision, and
if ActionableScore adjusted impact level of ALKERNEL, then you would see
self-readable flags above like INCREASED_TO_HIGH_BASED_ON_ACTIONABLESCOREHIGHEREQTHAN7.
For an AL-KERNEL result of MODERATE, this report uses the following
additional presentation split:
ActionableScore below 5 -> MODERATE REGULAR
ActionableScore 5 or more -> MODERATE 7.0
The distinction between MODERATE REGULAR and MODERATE 7.0 makes it
possible to identify Moderate issues that should receive manual analysis
and fixes before lower-priority MODERATE REGULAR issues. In many cases,
MODERATE REGULAR fixes may wait for a later rebase or routine update.
There is one override in which MODERATE REGULAR becomes MODERATE 7.0
even when the ActionableScore is below 5. When the AL-KERNEL result
contains the KPANIC flag, a MODERATE result is always presented as
MODERATE 7.0. The KPANIC flag selected with few regexps without
usage of AI at all, so it helps to detect cases when Kernel Crash happens
and similar (to filter False-Negative results from the LLM usage).
KPANIC indicates that a reliable kernel crash, kernel panic, or similarly
serious kernel availability impact was identified by the classification
workflow.
AL-KERNEL base severity for this report: MODERATE
KPANIC detected for this report: NO
Published priority for this report (same as in Subject): MODERATE 7.0
These results are intended to support engineering triage. They are
machine-generated estimates, and cases marked for manual review should
be validated by a human security engineer before final disposition.
For more info read docs linked from here: https://kernelcve.org/
(and you can submit you own patch there to generate such a report
for non-existant CVE-id yet).
Note that in many cases this AI tool selects higher severity, than
real is (means you can expect Importants instead of Moderate 7.0 or
Moderates 7.0 instead of regular Moderates). If you see such cases,
please use reply email interface to add additional manual analyses
info to this particular CVE.
And please, please, let me know when you see Lows instead of Importants
or Important instead of Low (because particular for such cases I
need to tune this AI tool to make it better for this one and next similar).
My contact email for such notifications is [email protected] (and both
send reply to CVE record itself too and see "reply" button below for howto reply).
reply other threads:[~2026-06-24 19:27 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --from, and --in-reply-to
switches of git-send-email(1) and next cmd tested by kernelcve.org admin:
git send-email --smtp-server=mail.kernelcve.org --smtp-server-port=25 --smtp-auth=none --from='Your Name <youremail@domain.is>' --suppress-cc=all --no-cc \
--in-reply-to=cve-2026-52967.5a10b31feee2dc0e6b675dff@kernelcve.org \
[email protected] \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
The file with msg could look like this then:
cat YOUR_REPLY
Subject: Re: [CVE-2026-64206][MODERATE REGULAR] Bluetooth: L2CAP test
Just testing public-inbox replies.
Thanks,
MyName
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox