In the Linux kernel, the following vulnerability has been resolved: smb: client: restore the data_offset bound in is_valid_oplock_break() Commit… (CVE-2026-89630)
A vulnerability in the Linux kernel's SMB client was resolved by restoring the data_offset bound check in the is_valid_oplock_break() function. A previous commit changed how the message length was calculated, causing the check to become ineffective and potentially allowing invalid data offsets. The fix uses the correct total_read value to properly enforce the data offset bound.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel SMB client arose from a change in commit 83bfbd0bb902 that altered the calculation of the SMB message length by removing the RFC1002 header from smb_hdr. This change caused the data_offset bound check in is_valid_oplock_break() to become ineffective because the length calculation resulted in zero, allowing the check to pass incorrectly. The fix restores the use of total_read, which now correctly represents the message length, ensuring the data_offset bound is properly enforced and preventing potential read overflow issues.
Potential Impact
The ineffective data_offset bound check could allow invalid or out-of-bounds data offsets in SMB oplock break messages, potentially leading to read overflows or memory corruption within the SMB client implementation in the Linux kernel. This could affect system stability or security when processing SMB messages.
Mitigation Recommendations
A fix has been implemented in the Linux kernel source code to restore the correct data_offset bound check in is_valid_oplock_break(). Users should apply the official kernel update or patch that includes this fix to mitigate the vulnerability.
In the Linux kernel, the following vulnerability has been resolved: smb: client: restore the data_offset bound in is_valid_oplock_break() Commit… (CVE-2026-89630)
Description
A vulnerability in the Linux kernel's SMB client was resolved by restoring the data_offset bound check in the is_valid_oplock_break() function. A previous commit changed how the message length was calculated, causing the check to become ineffective and potentially allowing invalid data offsets. The fix uses the correct total_read value to properly enforce the data offset bound.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel SMB client arose from a change in commit 83bfbd0bb902 that altered the calculation of the SMB message length by removing the RFC1002 header from smb_hdr. This change caused the data_offset bound check in is_valid_oplock_break() to become ineffective because the length calculation resulted in zero, allowing the check to pass incorrectly. The fix restores the use of total_read, which now correctly represents the message length, ensuring the data_offset bound is properly enforced and preventing potential read overflow issues.
Potential Impact
The ineffective data_offset bound check could allow invalid or out-of-bounds data offsets in SMB oplock break messages, potentially leading to read overflows or memory corruption within the SMB client implementation in the Linux kernel. This could affect system stability or security when processing SMB messages.
Mitigation Recommendations
A fix has been implemented in the Linux kernel source code to restore the correct data_offset bound check in is_valid_oplock_break(). Users should apply the official kernel update or patch that includes this fix to mitigate the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gch3-h386-3492
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89630"]
Threat ID: 6aa4a00955bf5e2cf5a8665b
Added to database: 09/12/2026, 00:42:49 UTC
Last enriched: 09/12/2026, 01:01:01 UTC
Last updated: 09/12/2026, 01:01:01 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.