PT-2026-106498 · Linux · Linux

CVE-2026-98169

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential OOB read in smb3 enum snapshots()
If snapshot array size is smaller than GMT TOKEN SIZE, smb3 enum snapshots() sets ret data len to sizeof(struct smb snapshot array) without verifying the actual length of the server's reply.
Because SMB2 ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret data len exceeding the size of retbuf. The subsequent copy to user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret data len.
Fix this by rejecting replies shorter than sizeof(struct smb snapshot array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN SNAPSHOT ARRAY SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy to user() attempts to read.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98169

Produtos afetados

Linux