A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-43362

CVE-2026-43362: Linux Kernel SMB Encryption Vulnerability

CVE-2026-43362 is a data corruption flaw in the Linux Kernel SMB client that causes in-place encryption errors during write retries. This post covers the technical details, affected versions, impact, and mitigation.

Published: May 18, 2026

CVE-2026-43362 Overview

CVE-2026-43362 is a high-severity flaw in the Linux kernel SMB client that corrupts data during encrypted SMB2 write retries. The SMB2_write() function places write payload in iov[1..n] as part of rq_iov, and smb3_init_transform_rq() pointer-shares this structure. When crypt_message() encrypts iov[1] in-place, the original plaintext is replaced with ciphertext. On a replayable error, the retry resends the same iov[1] containing ciphertext instead of plaintext, corrupting data on the server. The flaw affects SFU mknod operations, MF symlinks, and on kernels prior to 6.10, synchronous writes that used this code path.

Critical Impact

Silent data corruption on SMB shares when connections are unstable and write retries occur, with no error returned to the application.

Affected Products

  • Linux Kernel (multiple stable branches)
  • Linux Kernel 7.0-rc1, 7.0-rc2, 7.0-rc3
  • SMB client subsystem (fs/smb/client)

Discovery Timeline

  • 2026-05-08 - CVE-2026-43362 published to NVD
  • 2026-05-15 - Last updated in NVD database

Technical Details for CVE-2026-43362

Vulnerability Analysis

The vulnerability resides in the Linux kernel SMB client write path, specifically in SMB2_write() within fs/smb/client/smb2pdu.c. The function constructs a request using an I/O vector array rq_iov, placing the write payload in iov[1..n]. When SMB3 encryption is negotiated, smb3_init_transform_rq() builds a transform request but only pointer-shares the original rq_iov rather than performing a deep copy.

The encryption routine crypt_message() then encrypts the buffer in place, overwriting the plaintext payload with ciphertext. If the server returns a replayable error or the connection drops, the SMB client retries the same request. The retry transmits already-encrypted data as if it were plaintext, which the server then attempts to encrypt again, producing corrupted output on disk. This is classified under [CWE-787] Out-of-Bounds Write due to the integrity violation in buffer handling.

Root Cause

The root cause is shared-pointer semantics between the original request and the transform request. Because rq_iov is not deep-copied before encryption, the original payload buffer is mutated. The asynchronous write path was unaffected because it uses rq_iter, which is deep-copied during transform construction.

Attack Vector

Exploitation requires network access to an SMB server and conditions that trigger write retries, such as unstable network links or transient server errors. An attacker positioned to induce reconnects on encrypted SMB sessions can cause silent data corruption on files written by victim clients. The CVSS vector indicates user interaction is required and the impact is on integrity and availability rather than confidentiality.

The fix moves the write payload into rq_iter via iov_iter_kvec(), ensuring smb3_init_transform_rq() performs a deep copy before encryption. Refer to the Linux Kernel Commit 438e77435 for the upstream patch.

Detection Methods for CVE-2026-43362

Indicators of Compromise

  • Unexplained file corruption on SMB shares accessed by Linux clients with SMB3 encryption enabled
  • Kernel log entries indicating SMB session reconnects or replayable write errors
  • Mismatched file checksums between client-side source data and server-side stored data
  • Increased SMB retransmissions correlated with corrupted writes on encrypted shares

Detection Strategies

  • Audit running kernel versions across Linux fleet and compare against fixed stable branch commits referenced in the vendor advisory
  • Monitor dmesg and /var/log/kern.log for cifs or smb reconnect messages combined with write errors
  • Implement integrity verification (file hashing) on critical data written to SMB3-encrypted shares from Linux clients

Monitoring Recommendations

  • Track SMB session stability metrics and correlate disconnect events with file write operations
  • Enable verbose CIFS logging via echo 7 > /proc/fs/cifs/cifsFYI in test environments to surface retry behavior
  • Centralize Linux kernel logs into a SIEM and alert on SMB error patterns coinciding with reconnects

How to Mitigate CVE-2026-43362

Immediate Actions Required

  • Inventory all Linux systems mounting SMB3-encrypted shares and identify kernels missing the upstream fix
  • Apply the patched kernel from your distribution as soon as it becomes available
  • For unstable network segments, schedule a maintenance window to reboot into the patched kernel

Patch Information

The fix has been merged into multiple stable kernel branches. Reference commits include 438e77435aee, 52327268224f, 92e64f1852f4, aea5e37388a0, and d78840a6a38d. The patch moves the write payload from rq_iov into rq_iter via iov_iter_kvec(), forcing a deep copy before encryption.

Workarounds

  • Disable SMB3 encryption on affected mounts where data sensitivity allows, removing seal from mount options
  • Stabilize network paths between Linux clients and SMB servers to reduce retry events
  • Restrict Linux SMB client usage to read-only mounts where feasible until patches are applied
bash
# Check current kernel version and CIFS module status
uname -r
modinfo cifs | grep -E '^(version|filename)'

# Inspect active SMB mounts for encryption (seal) option
cat /proc/mounts | grep cifs
mount | grep -i seal

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeOther

  • Vendor/TechLinux Kernel

  • SeverityHIGH

  • CVSS Score8.1

  • EPSS Probability0.02%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityHigh
  • AvailabilityHigh
  • CWE References
  • CWE-787
  • Vendor Resources
  • Linux Kernel Commit 438e77435

  • Linux Kernel Commit 52327268

  • Linux Kernel Commit 92e64f18

  • Linux Kernel Commit aea5e373

  • Linux Kernel Commit d78840a6
  • Related CVEs
  • CVE-2026-46239: Linux Kernel OV5647 PM Refcount Leak

  • CVE-2026-46235: Linux Kernel saa7164 Memory Vulnerability

  • CVE-2026-46230: Linux Kernel AMDGPU VCN3 OOB Vulnerability

  • CVE-2026-46224: Linux Kernel DRM/XE Memory Leak Bug
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English