smb/client: fix possible infinite loop and oob read in symlink_data()
Summary
| CVE | CVE-2026-52967 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-24 17:17:07 UTC |
| Updated | 2026-06-24 17:17:07 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite loop and oob read in symlink_data() On 32-bit architectures, the infinite loop is as follows: len = p->ErrorDataLength == 0xfffffff8 u8 *next = p->ErrorContextData + len next == p On 32-bit architectures, the out-of-bounds read is as follows: len = p->ErrorDataLength == 0xfffffff0 u8 *next = p->ErrorContextData + len next == (u8 *)p - 8 |
Risk And Classification
EPSS: 0.001800000 probability, percentile 0.077660000 (date 2026-06-25)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 76894f3e2f71177747b8b4763fb180e800279585 1cfa2d59f669db28d6292d10ff87ca6837c781b0 git | Not specified |
| CNA | Linux | Linux | affected 76894f3e2f71177747b8b4763fb180e800279585 b41598bf54b3fe528994e573df6008f8f4d0a4f4 git | Not specified |
| CNA | Linux | Linux | affected 76894f3e2f71177747b8b4763fb180e800279585 cd4b9b662f0fb9aa97ee6bf9034eca76fc6cab23 git | Not specified |
| CNA | Linux | Linux | affected 76894f3e2f71177747b8b4763fb180e800279585 97a05b0ae9ea5ec052be2eef0f9cc7ce03501bbb git | Not specified |
| CNA | Linux | Linux | affected 76894f3e2f71177747b8b4763fb180e800279585 1b9331b16b0ed9414dcf7583d8134bdfeb117aae git | Not specified |
| CNA | Linux | Linux | affected 76894f3e2f71177747b8b4763fb180e800279585 7d9a7f1f96cd617ee9e75bb22217c709038e26b8 git | Not specified |
| CNA | Linux | Linux | affected 2d046892a493d9760c35fdaefc3017f27f91b621 git | Not specified |
| CNA | Linux | Linux | affected 6.0.16 6.1 semver | Not specified |
| CNA | Linux | Linux | affected 6.1 | Not specified |
| CNA | Linux | Linux | unaffected 6.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.175 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.141 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.91 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.33 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.10 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/1b9331b16b0ed9414dcf7583d8134bdfeb117aae | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b41598bf54b3fe528994e573df6008f8f4d0a4f4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/97a05b0ae9ea5ec052be2eef0f9cc7ce03501bbb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7d9a7f1f96cd617ee9e75bb22217c709038e26b8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1cfa2d59f669db28d6292d10ff87ca6837c781b0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/cd4b9b662f0fb9aa97ee6bf9034eca76fc6cab23 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.