Apple patched two kernel memory disclosure vulnerabilities in the macOS smbfs driver, tracked as CVE-2021-30844 and CVE-2021-30845, affecting macOS Big Sur 11.0 through 11.2.3. Both flaws could expose adjacent kernel heap data during SMB operations, creating conditions that could aid further exploitation. STAR Labs reported that Apple was notified in June and released fixes alongside security updates for affected systems.
CVE-2021-30844 stems from the SMBIOC_T2RQ ioctl path, where attacker-controlled data copied into t2p->t_name may not be NULL-terminated before later string handling, causing an out-of-bounds read and leaking kernel memory to an SMB server. CVE-2021-30845 affects smbfs_mount, where insufficient validation of unique_id_len against the fixed-size unique_id buffer in smb_mount_args can also trigger an out-of-bounds read during a mount request. Proof-of-concept demonstrations used fake or controlled SMB servers to show unintended kernel data disclosure, and the recommended mitigation is to update macOS to the latest available version.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
STAR Labs publicly released advisories for CVE-2021-30844 and CVE-2021-30845, including technical root-cause analysis and proof-of-concept demonstrations showing kernel memory disclosure to SMB infrastructure. The write-ups documented affected versions, exploitation conditions, and patch timing.
Apple released fixes for the two smbfs vulnerabilities, addressing an out-of-bounds read in SMBIOC_T2RQ handling and another in smbfs_mount unique_id_len processing. Users were advised to update macOS to the latest available version.
STAR Labs disclosed CVE-2021-30844 and CVE-2021-30845 to Apple. Both vulnerabilities affected macOS Big Sur 11.0 through 11.2.3 and could leak kernel memory via out-of-bounds reads in the smbfs kernel extension.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.