In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applies… (CVE-2026-68431)
A vulnerability in the Linux kernel's ksmbd component allowed certain SMB2 transform requests to bypass minimum PDU size validation. This could lead to reading beyond the allocated request buffer and potentially leaking data to unauthenticated clients. The issue was resolved by enforcing validation on ordinary SMB2 requests and requiring encryption transform requests to include both a transform header and an SMB2 header, thereby rejecting truncated requests early.
AI Analysis
Technical Summary
The Linux kernel's ksmbd SMB server component had a flaw where the minimum SMB2 Protocol Data Unit (PDU) size check was only applied when the ProtocolId was SMB2_PROTO_NUMBER. Packets with SMB2_TRANSFORM_PROTO_NUM could bypass this check even if the negotiated dialect did not support transform handling. On SMB 2.1 connections, this allowed short transform packets to reach init_smb2_rsp_hdr(), which misinterpreted the packet as a full SMB2 header and read beyond the allocated buffer, potentially leaking data to unauthenticated clients. The fix converts compression transform packets to ordinary SMB2 messages before validation and enforces minimum PDU size checks and header requirements to reject truncated or malformed requests before processing.
Potential Impact
An unauthenticated attacker could send specially crafted SMB2 transform packets that bypass minimum size validation, causing the server to read beyond allocated memory buffers. This could result in information disclosure of kernel memory contents to the attacker. No known exploits in the wild have been reported. The vulnerability affects SMB 2.1 connections where transform handling is not properly validated.
Mitigation Recommendations
A fix has been implemented in the Linux kernel ksmbd component that enforces minimum PDU size validation for transform requests and rejects truncated requests before allocation. Users should apply the official kernel updates that include this fix. Since no patch links or vendor advisories are provided here, check the Linux kernel mailing lists or distribution security advisories for the relevant fixed kernel versions. No additional mitigations are indicated by the vendor advisory.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applies… (CVE-2026-68431)
Description
A vulnerability in the Linux kernel's ksmbd component allowed certain SMB2 transform requests to bypass minimum PDU size validation. This could lead to reading beyond the allocated request buffer and potentially leaking data to unauthenticated clients. The issue was resolved by enforcing validation on ordinary SMB2 requests and requiring encryption transform requests to include both a transform header and an SMB2 header, thereby rejecting truncated requests early.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's ksmbd SMB server component had a flaw where the minimum SMB2 Protocol Data Unit (PDU) size check was only applied when the ProtocolId was SMB2_PROTO_NUMBER. Packets with SMB2_TRANSFORM_PROTO_NUM could bypass this check even if the negotiated dialect did not support transform handling. On SMB 2.1 connections, this allowed short transform packets to reach init_smb2_rsp_hdr(), which misinterpreted the packet as a full SMB2 header and read beyond the allocated buffer, potentially leaking data to unauthenticated clients. The fix converts compression transform packets to ordinary SMB2 messages before validation and enforces minimum PDU size checks and header requirements to reject truncated or malformed requests before processing.
Potential Impact
An unauthenticated attacker could send specially crafted SMB2 transform packets that bypass minimum size validation, causing the server to read beyond allocated memory buffers. This could result in information disclosure of kernel memory contents to the attacker. No known exploits in the wild have been reported. The vulnerability affects SMB 2.1 connections where transform handling is not properly validated.
Mitigation Recommendations
A fix has been implemented in the Linux kernel ksmbd component that enforces minimum PDU size validation for transform requests and rejects truncated requests before allocation. Users should apply the official kernel updates that include this fix. Since no patch links or vendor advisories are provided here, check the Linux kernel mailing lists or distribution security advisories for the relevant fixed kernel versions. No additional mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6pm5-g7cv-g948
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-68431"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b6abf8831d539cdfa08
Added to database: 08/12/2026, 16:12:26 UTC
Last enriched: 08/12/2026, 17:20:29 UTC
Last updated: 08/13/2026, 00:41:14 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.