PT-2026-106497 · Linux · Linux

CVE-2026-98168

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix reparse buffer bounds in cifs query reparse point()
In cifs query reparse point(), the start >= end check before casting to struct reparse data buffer * only ensures the start pointer is within the response. It fails to verify that there is enough space remaining for the fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining, the check passes, but subsequent reads of ReparseTag and ReparseDataLength will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the reparse data buffer structure before accessing its fields.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98168

Affected Products

Linux