Answer in brief
CVE-2026-89637 records a Unknown severity vulnerability in smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=316cf94a910f6f93d43cc574359d163ccae098a3 <9eed72e9534b10a6d9f8f5146feff3db53aebdba || >=316cf94a910f6f93d43cc574359d163ccae098a3 <5e6533a683f6a851158d9f33fb4ea8f4f25d7f84 || >=316cf94a910f6f93d43cc574359d163ccae098a3 <730d0bb19507b9e19c2fe5343109ac618e2fbce5 | 9eed72e9534b10a6d9f8f5146feff3db53aebdba, 5e6533a683f6a851158d9f33fb4ea8f4f25d7f84, 730d0bb19507b9e19c2fe5343109ac618e2fbce5 |
| Linux/Linuxgeneric | 3.6 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid->resp_buf set, mid->multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid->resp_buf with the new buffer (leaking the primary buffer) and, because mid->multiRsp is set, skips the server->smallbuf/bigbuf NULL-out. When the user thread frees mid->resp_buf, server->smallbuf or server->bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid->multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid->resp_buf or the server buffer pointers.
Quoted source text, attributed separately from HOL analysis.