PT-2026-106496 · Linux · Linux

CVE-2026-98167

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix server->total read for compound encrypted PDUs
In receive encrypted standard(), server->total read is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifs handle standard() passes this full size to smb2 check message(), causing the PDU length guards to incorrectly validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation, leading to out-of-bounds reads in smb2 get data area len().
Fix this by setting server->total read to the true length of the current sub-PDU: next cmd for non-last sub-PDUs, and the remaining pdu length for the last one.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98167

Produtos afetados

Linux