PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72310 Linux CVE debrief

The Linux kernel has a vulnerability in the smb: client: fix overflow in passthrough ioctl bounds check. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check, allowing for a potential out-of-bounds read. This vulnerability affects Linux kernel developers and users, as well as security teams monitoring for potential malicious server activity. The vulnerability is caused by an overflow in the passthrough ioctl bounds check in the Linux kernel's smb client. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, which can wrap in 32-bit arithmetic before the result is compared against the response buffer length. Evidence is limited to public CVE details and NVD information. Defenders should verify affected systems, review official advisories, and monitor for potential malicious activity. To address this vulnerability, defenders should apply patches to fix the overflow in passthrough ioctl bounds check, use size_add() for the offset plus length check to prevent overflow, and monitor for potential malicious server activity.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and users, as well as security teams monitoring for potential malicious server activity, should review and apply patches to prevent exploitation. Affected systems and deployments should be identified and prioritized for remediation. Security teams should also monitor for potential malicious activity and review compensating controls for exposed systems. Additionally, operators and platform administrators should be aware of the vulnerability and its potential impact on their systems. Vulnerability management and security teams should track exceptions and retest remediated assets to ensure the vulnerability is properly addressed. This may involve reviewing system logs and monitoring for suspicious activity. Asset inventory and configuration management may also be necessary to identify and prioritize affected systems. Rollback and change window planning may be required to ensure timely remediation. Source tracking and monitoring may also be necessary to detect and respond to potential exploitation attempts. Overall, a coordinated effort is required to address this vulnerability and prevent potential exploitation. This includes reviewing and applying patches, monitoring for malicious activity, and implementing compensating controls as needed. By taking these steps, organizations can help protect their systems and prevent potential exploitation of this vulnerability. It is also important to note that this vulnerability has been publicly disclosed and may be targeted by malicious actors. Therefore, it is essential to prioritize remediation and implement necessary controls to prevent exploitation. This may involve working with vendors, security teams, and other stakeholders to ensure that affected systems are properly patched and secured. By taking a proactive and coordinated approach, organizations can help prevent potential exploitation of this vulnerability and protect their systems and data. Finally, it is essential to review and update incident response plans to ensure that they are prepared to respond to potential exploitation attempts. This may involve identifying and prioritizing affected systems, reviewing and updating incident response,

Technical summary

The vulnerability is caused by an overflow in the passthrough ioctl bounds check in the Linux kernel's smb client. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, which can wrap in 32-bit arithmetic before the result is compared against the response buffer length. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check, allowing for a potential out-of-bounds read.

Defensive priority

High

Recommended defensive actions

  • Apply the patch to fix the overflow in passthrough ioctl bounds check
  • Use size_add() for the offset plus length check to prevent overflow
  • Monitor for potential malicious server activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by an overflow in the passthrough ioctl bounds check in the Linux kernel's smb client. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, which can wrap in 32-bit arithmetic before the result is compared against the response buffer length. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check, allowing for a potential out-of-bounds read. Evidence is limited to public CVE details and NVD information. Defenders should verify affected systems, review official advisories, and monitor for potential malicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72310 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72310

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72310 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72310

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/160045fc943f6c46b227644261252c8a22b8a87a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1627e7d5c9b09721a141d07cedb178882f1ded67

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/175357ee0c596cb82054650dfa32fda51ad35aaa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/63feb687e89a3a52a31e6e01764117cc500f1974

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a4f27ad055392fa164f5649e89a3637b033c5fcc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b30771b69eafae750afb7385fbcc3d77ed3f3670

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.