CVE-2026-43362 Details
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in SMB2_write() SMB2_write() places write payload in iov[1..n] as part of rq_iov. smb3_init_transform_rq() pointer-shares rq_iov, so crypt_message() encrypts iov[1] in-place, replacing the original plaintext with ciphertext. On a replayable error, the retry sends the same iov[1] which now contains ciphertext instead of the original data, resulting in corruption. The corruption is most likely to be observed when connections are unstable, as reconnects trigger write retries that re-send the already-encrypted data. This affects SFU mknod, MF symlinks, etc. On kernels before 6.10 (prior to the netfs conversion), sync writes also used this path and were similarly affected. The async write path wasn't unaffected as it uses rq_iter which gets deep-copied. Fix by moving the write payload into rq_iter via iov_iter_kvec(), so smb3_init_transform_rq() deep-copies it before encryption.
A vulnerability in the Linux kernel's SMB client has been addressed, which involved in-place encryption corruption during the SMB2 write operation. This issue arises because the write payload is shared as part of the request I/O vector, leading to the encryption of data in place. When a replayable error occurs, the encrypted data is sent instead of the original plaintext, causing corruption. This problem is particularly noticeable with unstable connections, where write retries can inadvertently resend already-encrypted data. The vulnerability affects various operations, including SFU mknod and MF symlinks, and was present in kernel versions prior to 6.10, before the netfs conversion.
The vulnerability has been fixed by modifying the write payload handling. The payload is now moved into a separate request iterator before encryption, ensuring that the original data is preserved. Users should upgrade to the latest stable version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/438e77435aee2894d5edf90be5c87004a57f6258 | kernel.org | Patch |
| https://git.kernel.org/stable/c/52327268224fb9ccc7ecfbbdfdfff54b6e93c518 | kernel.org | Patch |
| https://git.kernel.org/stable/c/92e64f1852f455f57d0850989e57c30d7fac7d95 | kernel.org | Patch |
| https://git.kernel.org/stable/c/aea5e37388a080361110ab5790f57ae0af383650 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d78840a6a38d312dc1a51a65317bb67e46f0b929 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.11, < 6.6.130 >= 6.7, < 6.12.78 >= 6.13, < 6.18.19 >= 6.19, < 6.19.9 7.0 rc1 7.0 rc2 7.0 rc3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | New CVE Received | kernel.org |