Review reviewHigh

CVE-2026-52967

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite loop and oob read in symlink_data() On 32-bit architectures, the infinite loop is as follows: len = p->ErrorDataLength == 0xfffffff8 u8 *next = p->ErrorContextData + len next == p On 32-bit architectures, the out-of-bounds read is as follows: len = p->ErrorDataLength == 0xfffffff0 u8 *next = p->ErrorContextData + len next == (u8 *)p - 8

CVSS
8.1
EPSS
0.39%
32.0% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.39%
Technical severityCVSS 8.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix possible infinite loop and oob read in symlink_data() On 32-bit architectures, the infinite loop is as follows: len = p->ErrorDataLength == 0xfffffff8 u8 *next = p->ErrorContextData + len next == p On 32-bit architectures, the out-of-bounds read is as follows: len = p->ErrorDataLength == 0xfffffff0 u8 *next = p->ErrorContextData + len next == (u8 *)p - 8

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 76894f3e2f71177747b8b4763fb180e800279585 < 1cfa2d59f669db28d6292d10ff87ca6837c781b0, >= 76894f3e2f71177747b8b4763fb180e800279585 < b41598bf54b3fe528994e573df6008f8f4d0a4f4, >= 76894f3e2f71177747b8b4763fb180e800279585 < cd4b9b662f0fb9aa97ee6bf9034eca76fc6cab23, >= 76894f3e2f71177747b8b4763fb180e800279585 < 97a05b0ae9ea5ec052be2eef0f9cc7ce03501bbb, >= 76894f3e2f71177747b8b4763fb180e800279585 < 1b9331b16b0ed9414dcf7583d8134bdfeb117aae, >= 76894f3e2f71177747b8b4763fb180e800279585 < 7d9a7f1f96cd617ee9e75bb22217c709038e26b8, >= 2d046892a493d9760c35fdaefc3017f27f91b621, >= 6.0.16 < 6.1, >= 6.1, >= 6.0.16 < 6.1.175, >= 6.2 < 6.6.141, >= 6.7 < 6.12.91, >= 6.13 < 6.18.33, >= 6.19 < 7.0.10, 7.1
Fixed versions
6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CWE
CWE-125