PT-2026-106499 · Linux · Linux
CVE-2026-98170
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix OOB struct field reads in move smb2 ea to cifs()
In move smb2 ea to cifs(), the while (src size > 0) loop condition is
insufficient. It allows iteration to continue even if the remaining
src size is too small to contain a complete smb2 ea info structure.
Consequently, reads of ea name length and ea value length can occur
out-of-bounds.
Fix this by ensuring src size >= sizeof(*src) before attempting to read
any structure fields. Additionally, reject any next entry offset that is
smaller than sizeof(*src) or that would advance the pointer beyond the
available buffer.
Note that for calls where the server returns a malformed EA list, the
error returned to userspace changes from -ENODATA (getxattr) or
-ERANGE (listxattr) to -EIO. This correctly signals a server protocol
error rather than misleadingly indicating "attribute not present" or
"output buffer too small".
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux