cbcvebase.
CVE-2026-43362
published 2026-05-08

CVE-2026-43362: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in SMB2_write() SMB2_write() places write…

PriorityP341high8.1CVSS 3.1
AVNACLPRNUIRSUCNIHAH
EPSS
0.22%
12.3th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in SMB2_write() SMB2_write() places write payload in iov[1..n] as part of rq_iov. smb3_init_transform_rq() pointer-shares rq_iov, so crypt_message() encrypts iov[1] in-place, replacing the original plaintext with ciphertext. On a replayable error, the retry sends the same iov[1] which now contains ciphertext instead of the original data, resulting in corruption. The corruption is most likely to be observed when connections are unstable, as reconnects trigger write retries that re-send the already-encrypted data. This affects SFU mknod, MF symlinks, etc. On kernels before 6.10 (prior to the netfs conversion), sync writes also used this path and were similarly affected. The async write path wasn't unaffected as it uses rq_iter which gets deep-copied. Fix by moving the write payload into rq_iter via iov_iter_kvec(), so smb3_init_transform_rq() deep-copies it before encryption.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 026e93dc0a3eefb0be060bcb9ecd8d7a7fd5c398 < 438e77435aee2894d5edf90be5c87004a57f6258438e77435aee2894d5edf90be5c87004a57f6258
linuxlinux>= 026e93dc0a3eefb0be060bcb9ecd8d7a7fd5c398 < 52327268224fb9ccc7ecfbbdfdfff54b6e93c51852327268224fb9ccc7ecfbbdfdfff54b6e93c518
linuxlinux>= 026e93dc0a3eefb0be060bcb9ecd8d7a7fd5c398 < 92e64f1852f455f57d0850989e57c30d7fac7d9592e64f1852f455f57d0850989e57c30d7fac7d95
linuxlinux>= 026e93dc0a3eefb0be060bcb9ecd8d7a7fd5c398 < aea5e37388a080361110ab5790f57ae0af383650aea5e37388a080361110ab5790f57ae0af383650
linuxlinux>= 026e93dc0a3eefb0be060bcb9ecd8d7a7fd5c398 < d78840a6a38d312dc1a51a65317bb67e46f0b929d78840a6a38d312dc1a51a65317bb67e46f0b929
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.11 < 6.6.1306.6.130
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.96.19.9
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-azure-6.8
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-lowlatency
ubuntulinux-lowlatency-hwe-6.8
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-nvidia-lowlatency

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
vendor_redhat7.0MEDIUM
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.