CVE-2026-72310
Linux kernel SMB client ioctl bounds check overflow allows remote info disclosure/DoS
Is CVE-2026-72310 being exploited?
Not confirmed. CVE-2026-72310 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.64% probability of exploitation in the next 30 days.
How severe is CVE-2026-72310?
CVE-2026-72310 is rated High. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72310?
Yes. A fix has been recorded for CVE-2026-72310. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72310 affect?
CVE-2026-72310 affects Linux kernel (SMB client - smb2_ioctl_query_info), Clients using CIFS/SMB passthrough ioctl. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72310?
Install kernel updates that fix smb2_ioctl_query_info; limit connections to untrusted SMB servers.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A malicious SMB server can craft a response to make the ioctl bounds check wrap, causing out‑of‑bounds kernel reads copied to userland (info disclosure) or crash (DoS).
Patch when possible
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < 175357ee0c596cb82054650dfa32fda51ad35aaa
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < dbd126539c098dba3159ce7d34b10b2daddcbd0f
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < 63feb687e89a3a52a31e6e01764117cc500f1974
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < 160045fc943f6c46b227644261252c8a22b8a87a
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < b30771b69eafae750afb7385fbcc3d77ed3f3670
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < 1627e7d5c9b09721a141d07cedb178882f1ded67
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < 1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9
- affected>= 2b1116bbe898aefdf584838448c6869f69851e0f and < a4f27ad055392fa164f5649e89a3637b033c5fcc
- affected2005c32ec99ee2490e8131b3953f3f212009ffea
- affected>= 5.4.69 and < 5.5
- affected5.5
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.