CVE-2026-64448

HIGHPre-NVD 8.28.2
EchelonGraph scoreMEDIUM confidence

This high-severity CVE scores 8.2 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.2%, top 92% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: epss, secondary
Trending — 5 sources updated this week
8.2EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 8.2Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

smb: client: restrict implied bcc[0] exemption to responses without data area

smb2_check_message() has a long-standing quirk that accepts a response whose calculated length is one byte larger than the bytes actually received ("server can return one byte more due to implied bcc[0]"). This was introduced to accommodate servers that omit the trailing bcc[0] overlap byte when no data area is present.

However, the exemption is applied unconditionally, regardless of whether the command actually carries a data area (has_smb2_data_area[]). When a response with a data area is subject to the +1 exemption, the reported data can extend one byte beyond the bytes actually received, yet smb2_check_message() still accepts it. The subsequent decoder then reads past the end of the receive buffer. This is reachable during NEGOTIATE and SESSION_SETUP, before the session is established.

The resulting out-of-bounds reads are visible under KASAN when mounting against a non-conforming server; both the SPNEGO/negTokenInit and the NTLMSSP challenge decoders are affected:

BUG: KASAN: slab-out-of-bounds in asn1_ber_decoder+0x16a7/0x1b00 Read of size 1 at addr ffff8880084d67c0 by task mount.cifs/81 CPU: 1 UID: 0 PID: 81 Comm: mount.cifs Not tainted 7.1.0-rc6 #1 Call Trace: dump_stack_lvl+0x4e/0x70 print_report+0x157/0x4c9 kasan_report+0xce/0x100 asn1_ber_decoder+0x16a7/0x1b00 decode_negTokenInit+0x19/0x30 SMB2_negotiate+0x31d9/0x4c90 cifs_negotiate_protocol+0x1f2/0x3f0 cifs_get_smb_ses+0x93f/0x17e0 cifs_mount_get_session+0x7f/0x3a0 cifs_mount+0xb4/0xcf0 cifs_smb3_do_mount+0x23a/0x1500 smb3_get_tree+0x3b0/0x630 vfs_get_tree+0x82/0x2d0 fc_mount+0x10/0x1b0 path_mount+0x50d/0x1de0 __x64_sys_mount+0x20b/0x270 do_syscall_64+0xee/0x590 entry_SYSCALL_64_after_hwframe+0x77/0x7f Allocated by task 85: kmem_cache_alloc_noprof+0x106/0x380 mempool_alloc_noprof+0x116/0x1e0 cifs_small_buf_get+0x31/0x80 allocate_buffers+0x10d/0x2b0 cifs_demultiplex_thread+0x1d5/0x1d50 kthread+0x2c6/0x390 ret_from_fork+0x36e/0x5a0 ret_from_fork_asm+0x1a/0x30 The buggy address is located 0 bytes to the right of allocated 448-byte region [ffff8880084d6600, ffff8880084d67c0) which belongs to the cache cifs_small_rq of size 448

BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x36/0x50 Read of size 329 at addr ffff88800726c678 by task mount.cifs/89 CPU: 0 UID: 0 PID: 89 Comm: mount.cifs Tainted: G B 7.1.0-rc6 #1 Call Trace: dump_stack_lvl+0x4e/0x70 print_report+0x157/0x4c9 kasan_report+0xce/0x100 kasan_check_range+0x10f/0x1e0 __asan_memcpy+0x23/0x60 kmemdup_noprof+0x36/0x50 decode_ntlmssp_challenge+0x457/0x680 SMB2_sess_auth_rawntlmssp_negotiate+0x6f0/0xcb0 SMB2_sess_setup+0x219/0x4f0 cifs_setup_session+0x248/0xaf0 cifs_get_smb_ses+0xf79/0x17e0 cifs_mount_get_session+0x7f/0x3a0 cifs_mount+0xb4/0xcf0 cifs_smb3_do_mount+0x23a/0x1500 smb3_get_tree+0x3b0/0x630 vfs_get_tree+0x82/0x2d0 fc_mount+0x10/0x1b0 path_mount+0x50d/0x1de0 __x64_sys_mount+0x20b/0x270 do_syscall_64+0xee/0x590 entry_SYSCALL_64_after_hwframe+0x77/0x7f Allocated by task 93: kmem_cache_alloc_noprof+0x106/0x380 mempool_alloc_noprof+0x116/0x1e0 cifs_small_buf_get+0x31/0x80 allocate_buffers+0x10d/0x2b0 cifs_demultiplex_thread+0x1d5/0x1d50 kthread+0x2c6/0x390 ret_from_fork+0x36e/0x5a0 ret_from_fork_asm+0x1a/0x30 The buggy address is located 120 bytes inside of allocated 448-byte region [ffff88800726c600, ffff88800726c7c0) which belongs to the cache cifs_small_rq of size 448

Restrict the +1 exemption to responses that have no data area, so that it still covers the bcc[0] omission it was meant for. When a data area is present, the +1 discrepancy instead means the reported data length overruns the ---truncated---

CVSS v3
8.2
EG Score
8.2(medium)
EG Risk
41(Track)
EG Risk 41/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity82% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
38%
KEV
Not listed

Published

July 25, 2026

Last Modified

July 27, 2026

Advisory Details (8)

Auto-updated Jul 27, 2026
No patch confirmed yet.
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/ceb875a375dedbf51c9425c1d13a2d7a8435c08c
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/8d0bbc78046d264bbf6a574ea6f9072258a43e35
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/6e9d10f62773b99bd927940fd9cbdfe7207e23ff
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/573e502d14714d2947e22e7eff40ec20a6a44a42
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/419ec1b604d7fb60c10aec2dc062371f9fcd4940
generic

smb: client: restrict implied bcc[0] exemption to responses without data area - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/31c6312608c60b72a1feb99a5afb680645a3e8a3

Vendor Advisories for CVE-2026-64448(2)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Data Freshness Timeline

(refreshed 15× in last 7d / 15× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-27 14:14 UTCEPSS rescore
  2. 2026-07-27 05:26 UTCEG score recompute
  3. 2026-07-27 05:26 UTCGHSA enrichment
  4. 2026-07-27 05:13 UTCEG score recompute 8.20
  5. 2026-07-27 05:13 UTCGHSA enrichment
  6. 2026-07-27 05:12 UTCMITRE cvelistV5CVSS v3 → 8.2 · severity → HIGH
  7. 2026-07-26 14:54 UTCEPSS rescore
  8. 2026-07-26 14:54 UTCEPSS rescore
  9. 2026-07-26 02:47 UTCEG score recompute
  10. 2026-07-26 02:47 UTCGHSA enrichment
  11. 2026-07-25 14:18 UTCEPSS rescore
  12. 2026-07-25 14:18 UTCEPSS rescore
  13. 2026-07-25 10:39 UTCNVD update
  14. 2026-07-25 09:26 UTCEG score recompute
  15. 2026-07-25 09:21 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-64448?
CVE-2026-64448 is a high vulnerability published on July 25, 2026. In the Linux kernel, the following vulnerability has been resolved: smb: client: restrict implied bcc[0] exemption to responses without data area smb2checkmessage() has a long-standing quirk that accepts a response whose calculated length is one byte larger than the bytes actually received ("server…
When was CVE-2026-64448 disclosed?
CVE-2026-64448 was first published in the National Vulnerability Database on July 25, 2026, with the most recent update on July 27, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-64448 actively exploited?
CVE-2026-64448 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 62.4% of all scored CVEs.
What is the CVSS score of CVE-2026-64448?
CVE-2026-64448 has a CVSS v3 base score of 8.2 (NVD).
How do I remediate CVE-2026-64448?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-64448, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-64448

Explore →

Is Your Infrastructure Affected by CVE-2026-64448?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.