PT-2026-106499 · Linux · Linux

CVE-2026-98170

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix OOB struct field reads in move smb2 ea to cifs()
In move smb2 ea to cifs(), the while (src size > 0) loop condition is insufficient. It allows iteration to continue even if the remaining src size is too small to contain a complete smb2 ea info structure. Consequently, reads of ea name length and ea value length can occur out-of-bounds.
Fix this by ensuring src size >= sizeof(*src) before attempting to read any structure fields. Additionally, reject any next entry offset that is smaller than sizeof(*src) or that would advance the pointer beyond the available buffer.
Note that for calls where the server returns a malformed EA list, the error returned to userspace changes from -ENODATA (getxattr) or -ERANGE (listxattr) to -EIO. This correctly signals a server protocol error rather than misleadingly indicating "attribute not present" or "output buffer too small".
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98170

Affected Products

Linux