PT-2026-106499 · Linux · Linux

CVE-2026-98170

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix OOB struct field reads in move smb2 ea to cifs()
In move smb2 ea to cifs(), the while (src size > 0) loop condition is insufficient. It allows iteration to continue even if the remaining src size is too small to contain a complete smb2 ea info structure. Consequently, reads of ea name length and ea value length can occur out-of-bounds.
Fix this by ensuring src size >= sizeof(*src) before attempting to read any structure fields. Additionally, reject any next entry offset that is smaller than sizeof(*src) or that would advance the pointer beyond the available buffer.
Note that for calls where the server returns a malformed EA list, the error returned to userspace changes from -ENODATA (getxattr) or -ERANGE (listxattr) to -EIO. This correctly signals a server protocol error rather than misleadingly indicating "attribute not present" or "output buffer too small".
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98170

Produtos afetados

Linux