Slab-Out-Of-Bounds Read Vulnerability in Linux Kernel's ksmbd for Remote Clients
CVE-2026-64578

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-64578?

A vulnerability exists in the ksmbd component of the Linux kernel that allows a remote client to exploit a flaw in the handling of compound SMB2 requests. Due to inadequate validation of the size of a compound request, the ksmbd_smb2_check_message function may read a two-byte field (StructureSize2) without confirming that the request contains sufficient data. As a result, this creates a risk of a slab-out-of-bounds read if the request is crafted with a specific size that bypasses normal checks. This security issue highlights the importance of robust input validation to prevent exploitation in shared environments.

Affected Version(s)

Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 2c307126ed8e7adddab82b8e31d962d3a2156ab1

Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9

Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.