---
id: CVE-2026-52967
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb/client: fix possible infinite loop and oob read in symlink_data()

  On 32-bit architectures, the infinite loop is as follows:

    len = p->ErrorDataLength == 0xffffff…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb/client: fix possible infinite loop and oob read in symlink_data()

  On 32-bit architectures, the infinite loop is as follows:

    len = p->ErrorDataLength == 0xffffff…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'
published: '2026-06-24'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52967'
references:
  - url: 'https://git.kernel.org/stable/c/1b9331b16b0ed9414dcf7583d8134bdfeb117aae'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1cfa2d59f669db28d6292d10ff87ca6837c781b0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7d9a7f1f96cd617ee9e75bb22217c709038e26b8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/97a05b0ae9ea5ec052be2eef0f9cc7ce03501bbb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b41598bf54b3fe528994e573df6008f8f4d0a4f4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cd4b9b662f0fb9aa97ee6bf9034eca76fc6cab23'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00538
epssPercentile: 0.43022
ingestedAt: '2026-07-11T13:13:25.037Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

smb/client: fix possible infinite loop and oob read in symlink_data()

On 32-bit architectures, the infinite loop is as follows:

  len = p->ErrorDataLength == 0xfffffff8
  u8 *next = p->ErrorContextData + len
  next == p

On 32-bit architectures, the out-of-bounds read is as follows:

  len = p->ErrorDataLength == 0xfffffff0
  u8 *next = p->ErrorContextData + len
  next == (u8 *)p - 8

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
