PT-2026-106496 · Linux · Linux
CVE-2026-98167
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix server->total read for compound encrypted PDUs
In receive encrypted standard(), server->total read is left at the
full decrypted frame size when walking sub-PDUs of a compound encrypted
frame. As a result, cifs handle standard() passes this full size
to smb2 check message(), causing the PDU length guards to incorrectly
validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation,
leading to out-of-bounds reads in smb2 get data area len().
Fix this by setting server->total read to the true length of the
current sub-PDU: next cmd for non-last sub-PDUs, and the remaining
pdu length for the last one.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux