{"id":"CVE-2026-89633","title":"kernel: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() (CVE-2026-89633)","summary":"A flaw was found in the Linux kernel's Server Message Block (SMB) client. The `coalesce_t2()` function processes server-supplied `DataOffset` fields without proper validation against buffer boundaries. A remote attacker could exploit this …","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:18:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89633.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89633.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89633"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532230"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89633"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89633"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89633.mbox"},{"url":"https://git.kernel.org/stable/c/033bc80019f07d158630df4e69b19a49010f54f1"},{"url":"https://git.kernel.org/stable/c/6343c1da561962688f203362d80d6a3bfa39fa1b"},{"url":"https://git.kernel.org/stable/c/672cf86aa6aa0fb4012ce4c3b3498df42ad67a4e"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00481,"epssPercentile":0.40482,"scores":{"vendor":7.1,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.474Z","slug":"CVE-2026-89633","body":"## Overview\n\nA flaw was found in the Linux kernel's Server Message Block (SMB) client. The `coalesce_t2()` function processes server-supplied `DataOffset` fields without proper validation against buffer boundaries. A remote attacker could exploit this by crafting malicious SMB responses. This could lead to out-of-bounds read and write operations, potentially resulting in information disclosure or arbitrary code execution.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89633.json)\n\n**kernel: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208114,"id":"CVE-2026-89633","ts":1789922715445,"field":"cvss","old":"7.1","new":"7"},{"seq":203011,"id":"CVE-2026-89633","ts":1789403733340,"field":"cvss","old":"9.8","new":"7.1"},{"seq":203010,"id":"CVE-2026-89633","ts":1789403733340,"field":"severity","old":"critical","new":"high"},{"seq":197836,"id":"CVE-2026-89633","ts":1789384320603,"field":"cvss","old":"7.1","new":"9.8"},{"seq":197835,"id":"CVE-2026-89633","ts":1789384320603,"field":"severity","old":"high","new":"critical"},{"seq":183729,"id":"CVE-2026-89633","ts":1789356677133,"field":"cvss","old":"9.8","new":"7.1"},{"seq":183728,"id":"CVE-2026-89633","ts":1789356677133,"field":"severity","old":"critical","new":"high"},{"seq":153470,"id":"CVE-2026-89633","ts":1789285350646,"field":"cvss","old":null,"new":"9.8"},{"seq":153469,"id":"CVE-2026-89633","ts":1789285350646,"field":"severity","old":"none","new":"critical"},{"seq":147586,"id":"CVE-2026-89633","ts":1789270211491,"field":"cvss","old":null,"new":"7.1"},{"seq":147585,"id":"CVE-2026-89633","ts":1789270211491,"field":"severity","old":"none","new":"high"},{"seq":109342,"id":"CVE-2026-89633","ts":1789183731509,"field":"cvss","old":null,"new":"7.1"},{"seq":109341,"id":"CVE-2026-89633","ts":1789183731509,"field":"severity","old":"none","new":"high"}]}