SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89632

HIGH · CVSS 8.2 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's SMB client, specifically in the handling of the `ReparseDataLength` field within the `reparse_buf_ptr()` function. An attacker could exploit this flaw to read beyond the allocated buffer, potentially leading to information disclosure or system instability. Organizations using Linux systems, particularly those relying on SMB for file sharing, should prioritize this issue to mitigate potential risks associated with data integrity and security.

CVE
CVE-2026-89632
Severity
HIGH
CVSS
8.2
EPSS
0.32%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() reparse_buf_ptr() reads buf->ReparseDataLength before checking that count covers the full fixed header: buf = (struct reparse_data_buffer *)((u8 *)io + off); len = sizeof(*buf); /* 8 bytes */ rdlen = le16_to_cpu(buf->ReparseDataLength); /* offset 4, 2 bytes */ if (count < len || count < rdlen + len) /* check comes after */ struct reparse_data_buffer has ReparseDataLength at offset 4. If a server returns OutputCount < 6, the read at offset 4-5 reaches past the end of the received data. The off+count bounds against iov_len were already validated, but that does not protect against count being smaller than sizeof(*buf). Split the check: verify count >= sizeof(*buf) before reading ReparseDataLength, then verify count covers the data region.