GO-2026-5051
Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2
Quick fix
GO-2026-5051 — github.com/cloudsoda/go-smb2: upgrade to the fixed version with the command below.
go get github.com/cloudsoda/go-smb2@v0.0.0-20260609183447-7b96c35f5f4b Details
ReadDir and ReadDirPlus parse the QUERY_DIRECTORY SMB response by advancing through entries using the server-supplied NextEntryOffset field. The pre-fix code does not bound next against the remaining buffer before re-slicing, and the entry decoder IsInvalid check performs length arithmetic in int after narrowing from uint16.
A guest or anonymous directory listing against an attacker-controlled or man-in-the-middle SMB server crashes the Go client process with a runtime panic when the response contains an entry whose NextEntryOffset is larger than the remaining buffer, or whose declared FileNameLength produces a length that does not match the actual buffer size.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 0.0.0-20260609183447-7b96c35f5f4b go get github.com/cloudsoda/go-smb2@v0.0.0-20260609183447-7b96c35f5f4b 0 No fixed version published yet for github.com/hirochachacha/go-smb2 (go modules). Pin to a known-safe version or switch to an alternative.