目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-90125— SMB客户端缓冲区泄漏

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,以下漏洞已得到修复: smb: 客户端:修复 smb2_new_read_req() 中的请求缓冲区泄漏 使用 分配请求缓冲区,但直到函数末尾才通过 将其发布给调用者。而在两者之间存在两个错误返回路径: 在这两种情况下,缓冲区既未被释放,也未被交还给调用者,因此发生了泄漏。调用者无法在之后进行清理:当返回非零值时, 会执行 ,从而跳过了 标签处的 调用;而且在该时刻, 尚未被赋值,因此无论如何都无法释放。 写路径从未出现过此问题。 是内联注册内存区域,并在失败时跳转到其释放标签,而不是直接返

AI 预测 7.0 利用难度: 中等 EPSS 0.21% · P10

可能的 ATT&CK 技术 1 AI

T1581

影响版本矩阵 12

厂商产品 版本范围状态
Linux Linux bd3dcc6a22a9186ed78da51ce09e889803552189< 58066940076b90c16e821fd6f9767cd979cbdb5e affected
bd3dcc6a22a9186ed78da51ce09e889803552189< 12092ed28434bf41e08d41e3c5269eb6b337fc02 affected
bd3dcc6a22a9186ed78da51ce09e889803552189< 442c5f1358ced0d4e716778ac06f1e323a7e4f21 affected
bd3dcc6a22a9186ed78da51ce09e889803552189< 73f6bdb0380486ab37fe12cd74de20abfaf5d3ae affected
bd3dcc6a22a9186ed78da51ce09e889803552189< deb6468f4164640e4dc875f008aa449cf55987a5 affected
4.16 affected
< 4.16 unaffected
6.6.157≤ 6.6.* unaffected
… +4 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-90125 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
smb: client: fix request buffer leak in smb2_new_read_req()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix request buffer leak in smb2_new_read_req() smb2_new_read_req() allocates the request buffer with smb2_plain_req_init() but only publishes it to the caller with *buf = req at the very end of the function. Two error returns sit in between: rc = smb2_plain_req_init(SMB2_READ, io_parms->tcon, server, (void **) &req, total_len); if (rc) return rc; if (server == NULL) return -ECONNABORTED; [...] rdata->mr = smbd_register_mr(server->smbd_conn, &rdata->subreq.io_iter, true, need_invalidate); if (!rdata->mr) return -EAGAIN; On either of them the buffer is neither released nor handed back, so it is leaked. The caller cannot clean up after it: smb2_async_readv() does 'goto out' on a non-zero return, which skips the cifs_small_buf_release(buf) at async_readv_out, and buf has not been assigned at that point in any case. The write path has never had this problem. smb2_async_writev() registers the memory region inline and jumps to its release label instead of returning: wdata->mr = smbd_register_mr(...); if (!wdata->mr) { rc = -EAGAIN; goto async_writev_out; } Commit b7972092199f ("cifs: smbd: Retry on memory registration failure") changed both sides from -ENOBUFS to -EAGAIN in a single patch, which puts the two shapes next to each other. Only the -EAGAIN return is reachable in practice, because smb2_plain_req_init() calls smb2_reconnect() first and that already fails with -EIO when server is NULL, before anything is allocated. Both returns are given the same treatment here rather than leaving one of them correct only by accident. Because -EAGAIN is a replayable error, the failure also reaches the retry block at the end of smb2_async_readv(), which marks the subrequest NETFS_SREQ_NEED_RETRY, so a failing registration can be retried rather than ending the I/O, and every attempt that reaches it leaks another buffer. smb2_should_replay() short-circuits on tcon->retry, so on a hard mount the attempt count is not bounded by the retrans setting. Only the asynchronous read path is affected. The synchronous SMB2_read() caller passes rdata == NULL and the memory registration block is guarded on rdata. The memory registration failure path was pointed out by the Sashiko AI reviewer while it was reviewing an unrelated patch to smb2_async_readv().
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux bd3dcc6a22a9186ed78da51ce09e889803552189 ~ 58066940076b90c16e821fd6f9767cd979cbdb5e -
Linux Linux 4.16 -

二、漏洞 CVE-2026-90125 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-90125 的情报信息

请登录查看更多情报信息。

CVE-2026-90125 补丁与修复 (5)

同批安全公告 · Linux · 2026-09-17 · 共 600 条

CVE-2026-90235 9.8 CRITICAL 内核sunrpc xprtsock并发读取修复
CVE-2026-90104 9.8 CRITICAL NFSv4.1 解码前未清空调用列表
CVE-2026-92489 9.8 CRITICAL Linux内核 xfrm 双重释放漏洞
CVE-2026-90173 9.8 CRITICAL SMB SmbDirect 释放完成队列漏洞
CVE-2026-90151 9.8 CRITICAL NFSv4客户端分配失败回调处理漏洞
CVE-2026-90110 9.4 CRITICAL inetpeer 随机化RB树节点比较
CVE-2026-90230 9.1 CRITICAL Linux内核Nvme-target堆越界读取漏洞
CVE-2026-90414 9.1 CRITICAL IB/isert拒绝声明超出实际接收数据的PDU
CVE-2026-90413 9.1 CRITICAL IB/isert 登录PDU数据长度校验漏洞
CVE-2026-93189 8.8 HIGH Linux HID核心使用已释放内存漏洞
CVE-2026-90256 8.8 HIGH Linux Bluetooth L2CAP 远程代码执行漏洞
CVE-2026-93042 8.8 HIGH Linux内核dmaengine模块资源耗尽漏洞
CVE-2026-90286 8.8 HIGH AMDGPU GFX6 计算队列PFP使用漏洞
CVE-2026-90255 8.8 HIGH Linux内核 Bluetooth 漏洞
CVE-2026-90425 8.8 HIGH Linux内核 5.x 内核漏洞
CVE-2026-90329 8.8 HIGH Linux 内核 HID 驱动探测清理同步漏洞
CVE-2026-90162 8.8 HIGH Linux ksmbd 锁授予UAF/双重释放竞态漏洞
CVE-2026-90240 8.8 HIGH Linux内核 IOMMU 别名拆除时刷新缓存错误
CVE-2026-90367 8.8 HIGH Linux内核MT7996驱动死锁漏洞
CVE-2026-90371 8.8 HIGH mt76 无线驱动 RXDMAD_C 竞态修复

显示前 20 条,共 600 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-90125

暂无评论


发表评论