DEBIAN-CVE-2026-89630
In the Linux kernel, the following vulnerability has been resolved: smb: client: restore the dataoffset bound in isvalidoplockbreak() Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smbhdr") changed the quantity this bound is measured against. It used to be srv->totalread minus the 4-byte RFC1002 preamble that totalread then included, so it was the SMB message length. The same commit stopped counting the preamble, and the mechanical substitution to srv->totalread - srv->pdusize left an expression that is identically zero: standardreceive3() reads MIDHEADERSIZE() bytes and then exactly pdulength - MIDHEADERSIZE() more, adding both to totalread. len is therefore 0, the subtraction below it wraps, and no _u32 DataOffset can exceed the result, so the check from commit 097f5863b1a0 ("cifs: read overflow in isvalidoplockbreak()") no longer rejects anything. Use total_read, which is now the message length on its own.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89630