VDB
KO

GO-2026-5051

Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2

Quick fix

GO-2026-5051 — github.com/cloudsoda/go-smb2: upgrade to the fixed version with the command below.

go get github.com/cloudsoda/go-smb2@v0.0.0-20260609183447-7b96c35f5f4b

Details

ReadDir and ReadDirPlus parse the QUERY_DIRECTORY SMB response by advancing through entries using the server-supplied NextEntryOffset field. The pre-fix code does not bound next against the remaining buffer before re-slicing, and the entry decoder IsInvalid check performs length arithmetic in int after narrowing from uint16.

A guest or anonymous directory listing against an attacker-controlled or man-in-the-middle SMB server crashes the Go client process with a runtime panic when the response contains an entry whose NextEntryOffset is larger than the remaining buffer, or whose declared FileNameLength produces a length that does not match the actual buffer size.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/cloudsoda/go-smb2
Introduced in: 0 Fixed in: 0.0.0-20260609183447-7b96c35f5f4b
Fix go get github.com/cloudsoda/go-smb2@v0.0.0-20260609183447-7b96c35f5f4b
Go / github.com/hirochachacha/go-smb2
Introduced in: 0

No fixed version published yet for github.com/hirochachacha/go-smb2 (go modules). Pin to a known-safe version or switch to an alternative.

References