CVE-2026-89631High· 7.0▾ TwilightA flaw was found in the Linux kernel's Server Message Block (SMB) client. A remote malicious SMB server could send a specially crafted tree connect response with a byte count that is too small. This incorrect handling can lead to an intege…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.4%
— → 5.7
none → medium
— → 9.1
none → critical
9.1 → 5.7
critical → medium
5.7 → 9.1
medium → critical
9.1 → 5.7
critical → medium
Last analysed / modified upstream
5.7 → 7
medium → high
A flaw was found in the Linux kernel's Server Message Block (SMB) client. A remote malicious SMB server could send a specially crafted tree connect response with a byte count that is too small. This incorrect handling can lead to an integer underflow, causing the client to read beyond an allocated memory buffer. Consequently, sensitive information from kernel memory may be exposed to a local user through the /proc/fs/cifs/DebugData interface.
kernel: smb: client: reject a tree connect response whose byte count is too small — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-18.
Affected:
No fix planned:
Not affected:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80985High· 7.0kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)
CVE-2026-80976High· 7.0kernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)
CVE-2026-80969Medium· 5.5kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)
CVE-2026-80972Medium· 5.5kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)
CVE-2026-80973High· 7.0kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)
CVE-2026-89443Medium· 5.5kernel: platform/x86: ISST: Validate level in perf mask ioctls (CVE-2026-89443)