PatchSiren cyber security CVE debrief
CVE-2026-72310 Linux CVE debrief
The Linux kernel has a vulnerability in the smb: client: fix overflow in passthrough ioctl bounds check. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check, allowing for a potential out-of-bounds read. This vulnerability affects Linux kernel developers and users, as well as security teams monitoring for potential malicious server activity. The vulnerability is caused by an overflow in the passthrough ioctl bounds check in the Linux kernel's smb client. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, which can wrap in 32-bit arithmetic before the result is compared against the response buffer length. Evidence is limited to public CVE details and NVD information. Defenders should verify affected systems, review official advisories, and monitor for potential malicious activity. To address this vulnerability, defenders should apply patches to fix the overflow in passthrough ioctl bounds check, use size_add() for the offset plus length check to prevent overflow, and monitor for potential malicious server activity.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and users, as well as security teams monitoring for potential malicious server activity, should review and apply patches to prevent exploitation. Affected systems and deployments should be identified and prioritized for remediation. Security teams should also monitor for potential malicious activity and review compensating controls for exposed systems. Additionally, operators and platform administrators should be aware of the vulnerability and its potential impact on their systems. Vulnerability management and security teams should track exceptions and retest remediated assets to ensure the vulnerability is properly addressed. This may involve reviewing system logs and monitoring for suspicious activity. Asset inventory and configuration management may also be necessary to identify and prioritize affected systems. Rollback and change window planning may be required to ensure timely remediation. Source tracking and monitoring may also be necessary to detect and respond to potential exploitation attempts. Overall, a coordinated effort is required to address this vulnerability and prevent potential exploitation. This includes reviewing and applying patches, monitoring for malicious activity, and implementing compensating controls as needed. By taking these steps, organizations can help protect their systems and prevent potential exploitation of this vulnerability. It is also important to note that this vulnerability has been publicly disclosed and may be targeted by malicious actors. Therefore, it is essential to prioritize remediation and implement necessary controls to prevent exploitation. This may involve working with vendors, security teams, and other stakeholders to ensure that affected systems are properly patched and secured. By taking a proactive and coordinated approach, organizations can help prevent potential exploitation of this vulnerability and protect their systems and data. Finally, it is essential to review and update incident response plans to ensure that they are prepared to respond to potential exploitation attempts. This may involve identifying and prioritizing affected systems, reviewing and updating incident response,
Technical summary
The vulnerability is caused by an overflow in the passthrough ioctl bounds check in the Linux kernel's smb client. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, which can wrap in 32-bit arithmetic before the result is compared against the response buffer length. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check, allowing for a potential out-of-bounds read.
Defensive priority
High
Recommended defensive actions
- Apply the patch to fix the overflow in passthrough ioctl bounds check
- Use size_add() for the offset plus length check to prevent overflow
- Monitor for potential malicious server activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by an overflow in the passthrough ioctl bounds check in the Linux kernel's smb client. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, which can wrap in 32-bit arithmetic before the result is compared against the response buffer length. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check, allowing for a potential out-of-bounds read. Evidence is limited to public CVE details and NVD information. Defenders should verify affected systems, review official advisories, and monitor for potential malicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72310 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72310
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72310 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72310
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/160045fc943f6c46b227644261252c8a22b8a87a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1627e7d5c9b09721a141d07cedb178882f1ded67
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/175357ee0c596cb82054650dfa32fda51ad35aaa
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/63feb687e89a3a52a31e6e01764117cc500f1974
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a4f27ad055392fa164f5649e89a3637b033c5fcc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b30771b69eafae750afb7385fbcc3d77ed3f3670
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.