PT-2026-106498 · Linux · Linux
CVE-2026-98169
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential OOB read in smb3 enum snapshots()
If snapshot array size is smaller than GMT TOKEN SIZE,
smb3 enum snapshots() sets ret data len to
sizeof(struct smb snapshot array) without verifying the actual length
of the server's reply.
Because SMB2 ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret data len exceeding the size of retbuf. The subsequent
copy to user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret data len.
Fix this by rejecting replies shorter than
sizeof(struct smb snapshot array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN SNAPSHOT ARRAY SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy to user() attempts to read.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux