{"id":"CVE-2026-89631","title":"kernel: smb: client: reject a tree connect response whose byte count is too small (CVE-2026-89631)","summary":"A flaw was found in the Linux kernel's Server Message Block (SMB) client. A remote malicious SMB server could send a specially crafted tree connect response with a byte count that is too small. This incorrect handling can lead to an intege…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T22:33:58+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89631.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89631.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89631"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532089"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89631"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89631"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89631.mbox"},{"url":"https://git.kernel.org/stable/c/3be89e8039a85fa3b6cd5f9dcc4c1459eb356c2d"},{"url":"https://git.kernel.org/stable/c/411e484fe71a7f1028de617447edad9cb6d9d68a"},{"url":"https://git.kernel.org/stable/c/65deb18359341141d37dc86fc7853511be3c87a7"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00448,"epssPercentile":0.38332,"scores":{"vendor":5.7,"cna":9.1},"ingestedAt":"2026-09-14T15:23:07.474Z","slug":"CVE-2026-89631","body":"## Overview\n\nA flaw was found in the Linux kernel's Server Message Block (SMB) client. A remote malicious SMB server could send a specially crafted tree connect response with a byte count that is too small. This incorrect handling can lead to an integer underflow, causing the client to read beyond an allocated memory buffer. Consequently, sensitive information from kernel memory may be exposed to a local user through the `/proc/fs/cifs/DebugData` interface.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89631.json)\n\n**kernel: smb: client: reject a tree connect response whose byte count is too small** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208079,"id":"CVE-2026-89631","ts":1789922705728,"field":"cvss","old":"5.7","new":"7"},{"seq":208078,"id":"CVE-2026-89631","ts":1789922705728,"field":"severity","old":"medium","new":"high"},{"seq":202845,"id":"CVE-2026-89631","ts":1789403732644,"field":"cvss","old":"9.1","new":"5.7"},{"seq":202844,"id":"CVE-2026-89631","ts":1789403732644,"field":"severity","old":"critical","new":"medium"},{"seq":197830,"id":"CVE-2026-89631","ts":1789384320579,"field":"cvss","old":"5.7","new":"9.1"},{"seq":197829,"id":"CVE-2026-89631","ts":1789384320579,"field":"severity","old":"medium","new":"critical"},{"seq":183395,"id":"CVE-2026-89631","ts":1789356675185,"field":"cvss","old":"9.1","new":"5.7"},{"seq":183394,"id":"CVE-2026-89631","ts":1789356675185,"field":"severity","old":"critical","new":"medium"},{"seq":153466,"id":"CVE-2026-89631","ts":1789285350623,"field":"cvss","old":null,"new":"9.1"},{"seq":153465,"id":"CVE-2026-89631","ts":1789285350623,"field":"severity","old":"none","new":"critical"},{"seq":147696,"id":"CVE-2026-89631","ts":1789270211920,"field":"cvss","old":null,"new":"5.7"},{"seq":147695,"id":"CVE-2026-89631","ts":1789270211920,"field":"severity","old":"none","new":"medium"},{"seq":109452,"id":"CVE-2026-89631","ts":1789183731968,"field":"cvss","old":null,"new":"5.7"},{"seq":109451,"id":"CVE-2026-89631","ts":1789183731968,"field":"severity","old":"none","new":"medium"}]}