CVE-2024-26692 (GCVE-0-2024-26692)
Vulnerability from cvelistv5
Published
2024-04-03 14:54
Modified
2026-08-05 11:26
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is set by the server to an unexpected value which is not a multiple of 4096 (similarly if the user overrides the maximum write size by setting mount parm "wsize", but sets it to a value that is not a multiple of 4096). When negotiated write size is not a multiple of 4096 the netfs code can skip the end of the final page when doing large sequential writes, causing data corruption. This section of code is being rewritten/removed due to a large netfs change, but until that point (ie for the 6.3 kernel until now) we can not support non-standard maximum write sizes. Add a warning if a user specifies a wsize on mount that is not a multiple of 4096 (and round down), also add a change where we round down the maximum write size if the server negotiates a value that is not a multiple of 4096 (we also have to check to make sure that we do not round it down to zero).
Impacted products
Vendor Product Version
Linux Linux Version: d08089f649a0cfb2099c8551ac47eef0cc23fdf2
Version: d08089f649a0cfb2099c8551ac47eef0cc23fdf2
Version: d08089f649a0cfb2099c8551ac47eef0cc23fdf2
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:14:12.775Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4145ccff546ea868428b3e0fe6818c6261b574a9"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/63c35afd50e28b49c5b75542045a8c42b696dab9"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4860abb91f3d7fbaf8147d54782149bb1fc45892"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26692",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T15:53:00.719188Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:31.032Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/connect.c",
            "fs/smb/client/fs_context.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4145ccff546ea868428b3e0fe6818c6261b574a9",
              "status": "affected",
              "version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
              "versionType": "git"
            },
            {
              "lessThan": "63c35afd50e28b49c5b75542045a8c42b696dab9",
              "status": "affected",
              "version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
              "versionType": "git"
            },
            {
              "lessThan": "4860abb91f3d7fbaf8147d54782149bb1fc45892",
              "status": "affected",
              "version": "d08089f649a0cfb2099c8551ac47eef0cc23fdf2",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/connect.c",
            "fs/smb/client/fs_context.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "lessThan": "6.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.18",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.18",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.6",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Fix regression in writes when non-standard maximum write size negotiated\n\nThe conversion to netfs in the 6.3 kernel caused a regression when\nmaximum write size is set by the server to an unexpected value which is\nnot a multiple of 4096 (similarly if the user overrides the maximum\nwrite size by setting mount parm \"wsize\", but sets it to a value that\nis not a multiple of 4096).  When negotiated write size is not a\nmultiple of 4096 the netfs code can skip the end of the final\npage when doing large sequential writes, causing data corruption.\n\nThis section of code is being rewritten/removed due to a large\nnetfs change, but until that point (ie for the 6.3 kernel until now)\nwe can not support non-standard maximum write sizes.\n\nAdd a warning if a user specifies a wsize on mount that is not\na multiple of 4096 (and round down), also add a change where we\nround down the maximum write size if the server negotiates a value\nthat is not a multiple of 4096 (we also have to check to make sure that\nwe do not round it down to zero)."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The attacker-controlled input is the MaxWriteSize field of the SMB2 NEGOTIATE response received over TCP/445 from a remote SMB server, copied verbatim into server-\u003emax_write with no validation. A malicious/compromised server, a DFS-referral target, or an on-path attacker (MaxWriteSize is unsigned in the pre-auth NEGOTIATE and is not covered by FSCTL_VALIDATE_NEGOTIATE_INFO) supplies it purely over the network.\nAC:L - The server simply advertises a MaxWriteSize that is not a multiple of PAGE_SIZE (or zero); there is no race, no dependency on memory layout, and no condition outside the attacker\u0027s control. Every large sequential write on the mount then corrupts deterministically.\nPR:N - The attacker is the remote SMB peer and needs no credentials or privileges on the victim client; the poisoned MaxWriteSize is delivered in the NEGOTIATE response, which precedes session setup and authentication entirely.\nUI:R - The victim must mount a CIFS/SMB share from the attacker-controlled or compromised server, since wsize is fixed at mount time in cifs_mount_get_tcon(). This is minimal interaction \u2014 an /etc/fstab, autofs, or systemd automount does it with no human present \u2014 but a mount action is still required.\nS:U - The corruption and the stuck-writeback hang are confined to the mounting kernel\u0027s page cache and the mounted share, within the same security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:L - There is no kernel-memory disclosure, but the skipped tail regions mean in-place rewrites silently fail to overwrite: residual old file content (e.g. secrets a program believed it had replaced) persists on the share and stays readable to anyone with access to the current file. The exposure is bounded to those stale tail regions, so Low rather than High.\nI:H - The remote server fully controls how much of each page is silently discarded \u2014 up to 4095 of every 4096 bytes \u2014 while write(), close(), and fsync() all report success and the page cache masks the damage until eviction, so backups, databases, config files, and source trees are corrupted undetectably. This is complete, attacker-directed loss of integrity over all data written to the mount.\nA:H - With a server-advertised MaxWriteSize of 0, wsize becomes 0 and wdata-\u003ebytes is 0, so all three completion helpers early-return on !len and never undo the unconditional folio_start_writeback(), leaving folios permanently under writeback. That yields unkillable D-state tasks on fsync/sync/truncate/umount, permanently pinned pages, and an ever-growing NR_WRITEBACK that stalls system-wide dirty-page throttling."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:26:44.270Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4145ccff546ea868428b3e0fe6818c6261b574a9"
        },
        {
          "url": "https://git.kernel.org/stable/c/63c35afd50e28b49c5b75542045a8c42b696dab9"
        },
        {
          "url": "https://git.kernel.org/stable/c/4860abb91f3d7fbaf8147d54782149bb1fc45892"
        }
      ],
      "title": "smb: Fix regression in writes when non-standard maximum write size negotiated",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26692",
    "datePublished": "2024-04-03T14:54:53.343Z",
    "dateReserved": "2024-02-19T14:20:24.155Z",
    "dateUpdated": "2026-08-05T11:26:44.270Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/4145ccff546ea868428b3e0fe6818c6261b574a9\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/63c35afd50e28b49c5b75542045a8c42b696dab9\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/4860abb91f3d7fbaf8147d54782149bb1fc45892\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:14:12.775Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26692\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T15:53:00.719188Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:17.099Z\"}}], \"cna\": {\"title\": \"smb: Fix regression in writes when non-standard maximum write size negotiated\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 8.3, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The attacker-controlled input is the MaxWriteSize field of the SMB2 NEGOTIATE response received over TCP/445 from a remote SMB server, copied verbatim into server-\u003emax_write with no validation. A malicious/compromised server, a DFS-referral target, or an on-path attacker (MaxWriteSize is unsigned in the pre-auth NEGOTIATE and is not covered by FSCTL_VALIDATE_NEGOTIATE_INFO) supplies it purely over the network.\\nAC:L - The server simply advertises a MaxWriteSize that is not a multiple of PAGE_SIZE (or zero); there is no race, no dependency on memory layout, and no condition outside the attacker\u0027s control. Every large sequential write on the mount then corrupts deterministically.\\nPR:N - The attacker is the remote SMB peer and needs no credentials or privileges on the victim client; the poisoned MaxWriteSize is delivered in the NEGOTIATE response, which precedes session setup and authentication entirely.\\nUI:R - The victim must mount a CIFS/SMB share from the attacker-controlled or compromised server, since wsize is fixed at mount time in cifs_mount_get_tcon(). This is minimal interaction \\u2014 an /etc/fstab, autofs, or systemd automount does it with no human present \\u2014 but a mount action is still required.\\nS:U - The corruption and the stuck-writeback hang are confined to the mounting kernel\u0027s page cache and the mounted share, within the same security authority. No VM, IOMMU, or sandbox boundary is crossed.\\nC:L - There is no kernel-memory disclosure, but the skipped tail regions mean in-place rewrites silently fail to overwrite: residual old file content (e.g. secrets a program believed it had replaced) persists on the share and stays readable to anyone with access to the current file. The exposure is bounded to those stale tail regions, so Low rather than High.\\nI:H - The remote server fully controls how much of each page is silently discarded \\u2014 up to 4095 of every 4096 bytes \\u2014 while write(), close(), and fsync() all report success and the page cache masks the damage until eviction, so backups, databases, config files, and source trees are corrupted undetectably. This is complete, attacker-directed loss of integrity over all data written to the mount.\\nA:H - With a server-advertised MaxWriteSize of 0, wsize becomes 0 and wdata-\u003ebytes is 0, so all three completion helpers early-return on !len and never undo the unconditional folio_start_writeback(), leaving folios permanently under writeback. That yields unkillable D-state tasks on fsync/sync/truncate/umount, permanently pinned pages, and an ever-growing NR_WRITEBACK that stalls system-wide dirty-page throttling.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"d08089f649a0cfb2099c8551ac47eef0cc23fdf2\", \"lessThan\": \"4145ccff546ea868428b3e0fe6818c6261b574a9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d08089f649a0cfb2099c8551ac47eef0cc23fdf2\", \"lessThan\": \"63c35afd50e28b49c5b75542045a8c42b696dab9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d08089f649a0cfb2099c8551ac47eef0cc23fdf2\", \"lessThan\": \"4860abb91f3d7fbaf8147d54782149bb1fc45892\", \"versionType\": \"git\"}], \"programFiles\": [\"fs/smb/client/connect.c\", \"fs/smb/client/fs_context.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.3\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.3\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.6.18\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.6\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/smb/client/connect.c\", \"fs/smb/client/fs_context.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/4145ccff546ea868428b3e0fe6818c6261b574a9\"}, {\"url\": \"https://git.kernel.org/stable/c/63c35afd50e28b49c5b75542045a8c42b696dab9\"}, {\"url\": \"https://git.kernel.org/stable/c/4860abb91f3d7fbaf8147d54782149bb1fc45892\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nsmb: Fix regression in writes when non-standard maximum write size negotiated\\n\\nThe conversion to netfs in the 6.3 kernel caused a regression when\\nmaximum write size is set by the server to an unexpected value which is\\nnot a multiple of 4096 (similarly if the user overrides the maximum\\nwrite size by setting mount parm \\\"wsize\\\", but sets it to a value that\\nis not a multiple of 4096).  When negotiated write size is not a\\nmultiple of 4096 the netfs code can skip the end of the final\\npage when doing large sequential writes, causing data corruption.\\n\\nThis section of code is being rewritten/removed due to a large\\nnetfs change, but until that point (ie for the 6.3 kernel until now)\\nwe can not support non-standard maximum write sizes.\\n\\nAdd a warning if a user specifies a wsize on mount that is not\\na multiple of 4096 (and round down), also add a change where we\\nround down the maximum write size if the server negotiates a value\\nthat is not a multiple of 4096 (we also have to check to make sure that\\nwe do not round it down to zero).\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.18\", \"versionStartIncluding\": \"6.3\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.6\", \"versionStartIncluding\": \"6.3\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"6.3\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:26:44.270Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26692\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:26:44.270Z\", \"dateReserved\": \"2024-02-19T14:20:24.155Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-03T14:54:53.343Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…