PT-2026-106498 · Linux · Linux

CVE-2026-98169

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential OOB read in smb3 enum snapshots()
If snapshot array size is smaller than GMT TOKEN SIZE, smb3 enum snapshots() sets ret data len to sizeof(struct smb snapshot array) without verifying the actual length of the server's reply.
Because SMB2 ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret data len exceeding the size of retbuf. The subsequent copy to user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret data len.
Fix this by rejecting replies shorter than sizeof(struct smb snapshot array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN SNAPSHOT ARRAY SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy to user() attempts to read.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98169

Affected Products

Linux