PT-2026-106498 · Linux · Linux
CVE-2026-98169
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential OOB read in smb3 enum snapshots()
If snapshot array size is smaller than GMT TOKEN SIZE,
smb3 enum snapshots() sets ret data len to
sizeof(struct smb snapshot array) without verifying the actual length
of the server's reply.
Because SMB2 ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret data len exceeding the size of retbuf. The subsequent
copy to user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret data len.
Fix this by rejecting replies shorter than
sizeof(struct smb snapshot array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN SNAPSHOT ARRAY SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy to user() attempts to read.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux