Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-64257

smb: client: reject overlapping data areas in SMB2 responses
Back to all
CVE

CVE-2026-64257

smb: client: reject overlapping data areas in SMB2 responses

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject overlapping data areas in SMB2 responses

Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to

responses without data area") restricted the implied bcc[0] length

exception to responses without a data area. However, the overlap

handling in _smb2calcsize() clears datalength, which can make an

invalid response appear to have no data area and so qualify for the

exception.

Track data area overlap separately and reject such responses before

applying the length compatibility exceptions.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/36bfa52459e45c0d5b668de2f1c91f6dc5c67775, https://git.kernel.org/stable/c/445ece263131780dee273d727a4d6f11934feec7, https://git.kernel.org/stable/c/4a9d2657d3e05f6ed09c148cb127b4e58702275f, https://git.kernel.org/stable/c/57cba95f0e97c6f6e45e6731da30aff091bd7460, https://git.kernel.org/stable/c/8986c932905ea508d66da421eb2eb6e676ace1fe, https://git.kernel.org/stable/c/fdafa1e68dc75045b7b617e6e7d2854950804d83, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64257.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64257, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00664%
EPSS Percentile
0.50096%
Introduced Version
31c6312608c60b72a1feb99a5afb680645a3e8a3,573e502d14714d2947e22e7eff40ec20a6a44a42,419ec1b604d7fb60c10aec2dc062371f9fcd4940,ceb875a375dedbf51c9425c1d13a2d7a8435c08c,6e9d10f62773b99bd927940fd9cbdfe7207e23ff,53b7c271f06be4dd5cfc8c6ef552a8355c891a7f,0,5.10.261,5.15.212
Fix Available
445ece263131780dee273d727a4d6f11934feec7,36bfa52459e45c0d5b668de2f1c91f6dc5c67775,4a9d2657d3e05f6ed09c148cb127b4e58702275f,fdafa1e68dc75045b7b617e6e7d2854950804d83,57cba95f0e97c6f6e45e6731da30aff091bd7460,8986c932905ea508d66da421eb2eb6e676ace1fe,5.11,5.16,0:6.12.0-206.104.3.3.el9uek,0:6.12.0-206.104.3.3.el10uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading