← All Advisories

CVE-2026-93787

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93787

Key Details

CVECVE-2026-93787
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: bound dirent name against end of SMB response in cifs_filldir

cifs_filldir() copies the entry name out of an SMB1 TRANS2_FIND_FIRST /

FIND_NEXT response using a length (de.namelen) supplied by the server.

The kmalloc'd SMB response buffer is bounded, but nothing checks that

de.name + de.namelen still lies inside that buffer before the eventual

filldir64() -> verify_dirent_name() -> memchr() reads namelen bytes.

A hostile SMB1 server that returns an oversized FileNameLength in a

directory entry therefore causes memchr() to read past the end of the

response slab buffer. Reachable from any user who can list a directory

on a CIFS mount served by an attacker-controlled server (getdents64()

on the mounted directory):

BUG: KASAN: slab-out-of-bounds in memchr+0x71/0x80

Read of size 1 at addr ffff88800e0640cc by task poc/115

Call Trace:

dump_stack_lvl+0x64/0x80

print_report+0xce/0x620

kasan_report+0xec/0x120

memchr+0x71/0x80

filldir64+0x4c/0x6a0

cifs_filldir.constprop.0+0x9bb/0x1e00

cifs_readdir+0x2101/0x3380

iterate_dir+0x19c/0x520

__x64_sys_getdents64+0x126/0x210

do_syscall_64+0x107/0x5a0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

Pass the end-of-response pointer down to cifs_filldir() and reject

entries whose name would extend past that boundary.

This bug was discovered by Artiphishell's vTriage pipeline, which

generated a userspace reproducer (an emulated hostile SMB1 server plus

a getdents64() client) that reliably triggers the KASAN report on an

unpatched kernel. The fix below was drafted with the Claude coding

assistant; a userspace reproducer is available on request. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93787
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93787