CVE-2026-63909
Linux ksmbd heap OOB read via malformed SMB2_CREATE (2-byte OOB).
Is CVE-2026-63909 being exploited?
Not confirmed. CVE-2026-63909 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.63% probability of exploitation in the next 30 days.
How severe is CVE-2026-63909?
CVE-2026-63909 is rated High with a CVSS score of 8.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63909?
Yes. A fix has been recorded for CVE-2026-63909. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63909 affect?
CVE-2026-63909 affects Linux kernel (ksmbd SMB server), Linux distributions with ksmbd enabled. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63909?
Apply vendor/kernel updates or backport ksmbd fix immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker can trigger a 2-byte heap out-of-bounds read via ksmbd SMB2_CREATE, causing info disclosure or crash and aiding further exploitation.
Patch when possible
- affected>= 282cbbb476b9f35793452bc461934af4c7eca169 and < 5500ba1d410aed1eded3eb04a76b10cfb4409334
- affected>= f20adc4ef7428bc485ee83fd1a592252fb87718b and < f6324b4240cf0b26a84c33f68a1222d727ff4af2
- affected>= 325d4ac11f526cb8964cff14548ccf02d8c756d8 and < 0fe08c5776a798f46df1fd74b331be26bdd644d6
- affected>= 95e5aa3c3261da8c95b27d7aecf8ee39b9f86a4c and < d333af32e4451285e427f2d9c29de3a39f6f6d48
- affected>= 90089584b2e25c4510b7b987387b4405f0673ece and < 94215d55b09445993929f4fc966061d61de74929
- affected>= 151b1799861fde38087c08f613abc2843ef597b0 and < 4f7c131d2bdd7cd64b96f60d10be5ea72253f520
- affected>= d07b26f39246a82399661936dd0c853983cfade7 and < 0e60dafe97eca61721f3db456f97d97a80c6c8ae
- affected>= 6.6.140 and < 6.6.143
- affected>= 6.12.84 and < 6.12.93
- affected>= 6.18.25 and < 6.18.35
- affected>= 7.0.2 and < 7.0.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.