CVE-2026-89630
In the Linux kernel, the following vulnerability has been resolved:
smb: client: restore the dataoffset bound in isvalidoplockbreak()
Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr")
changed the quantity this bound is measured against. It used to be
srv->totalread minus the 4-byte RFC1002 preamble that totalread then
included, so it was the SMB message length. The same commit stopped
counting the preamble, and the mechanical substitution to
srv->totalread - srv->pdusize left an expression that is identically
zero: standardreceive3() reads MIDHEADER_SIZE() bytes and then exactly
pdulength - MIDHEADERSIZE() more, adding both to totalread.
len is therefore 0, the subtraction below it wraps, and no __u32
DataOffset can exceed the result, so the check from commit 097f5863b1a0
("cifs: read overflow in isvalidoplock_break()") no longer rejects
anything. Use total_read, which is now the message length on its own.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/5b16a1967a01ad4496a7206a87c3eb16f1df2b05, https://git.kernel.org/stable/c/ba22f575de9deeae4ae0859ca4315a7698226237, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89630.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89630, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git