CVE-2026-72310
CVE CVE-2026-72310EUVD EUVD-2026-59209Published 2026-08-15T05:55:26.000ZLast changed 2026-08-17T05:42:38.000ZCVSS 8.1
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix overflow in passthrough ioctl bounds check smb2_ioctl_query_info() validates the PASSTHRU_FSCTL response payload before copying it to userspace. The payload offset and length both come from 32-bit fields. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, so the addition can wrap in 32-bit arithmetic before the result is compared against the response buffer length. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check. The later copy_to_user() then reads from io_rsp + OutputOffset, outside the response buffer. Use size_add() for the offset plus length check so overflow is treated as out of bounds.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; 2b1116bbe898aefdf584838448c6869f69851e0f <a4f27ad055392fa164f5649e89a3637b033c5fcc; patch: 6.18.40; 2b1116bbe898aefdf584838448c6869f69851e0f <b30771b69eafae750afb7385fbcc3d77ed3f3670; 2b1116bbe898aefdf584838448c6869f69851e0f <160045fc943f6c46b227644261252c8a22b8a87a; 2b1116bbe898aefdf584838448c6869f69851e0f <dbd126539c098dba3159ce7d34b10b2daddcbd0f; patch: 6.12.97; patch: 6.6.145; 2b1116bbe898aefdf584838448c6869f69851e0f <1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9; 2005c32ec99ee2490e8131b3953f3f212009ffea; 2b1116bbe898aefdf584838448c6869f69851e0f <63feb687e89a3a52a31e6e01764117cc500f1974; patch: 7.2; patch: 6.1.178; patch: 5.10.261; patch: 7.1.5; 5.4.69 <5.5; 2b1116bbe898aefdf584838448c6869f69851e0f <1627e7d5c9b09721a141d07cedb178882f1ded67; 2b1116bbe898aefdf584838448c6869f69851e0f <175357ee0c596cb82054650dfa32fda51ad35aaa; 5.5; patch: 5.15.212
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.